Yes. Arcsight actually already has a DLP connector, so if you follow their guides with regards to the message format, you don't need to do anything around configuring the connector. SYSLOG of incident data is a response rule that can be configured on any policy. So you can send syslog events to any other SIEM system that will receive them.
Best place to get a "list" of variables that can be included is to go to look at the Email response rule (build a dummy one, for instance). On that screen, they list all the variables that can be included in the email message. These same variables can be used in the syslog message.
There is a message length constraint on syslog messages, but I don't recall what it is. This is dictated by the protocol, not the DLP application.
~Keith