When the syslog fires.. are all of those populated?
more info: https://kb-vontu.altiris.com/display/1n/kb/article.asp?aid=47666&link=
You can also try the following, these are from the Plugin.properties file, they may or may not work. This may require you to have some Lookups configured to use them.
Also keep in mind about the Custom Attributes, they might be able to be added to the syslog info too. You will need to experiment with this. I do know they can be used in an Email Response, so I would assume the same for a syslog response. They are called $ATTRIBUTE_24$ $ATTRIBUTE_25$. Which can be found when you mouse over the field in an incident.
__________________________________________________________________________________
incident info
date-detected
incident-id
protocol
message info
date-sent
subject
file-create-date
file-access-date
file-created-by
file-modified-by
file-owner
discover-content-root-path
discover-location
discover-name
discover-extraction-date
discover-server
discover-notes-database
discover-notes-url
endpoint-volume-name
endpoint-dos-volume-name
endpoint-application-name
endpoint-application-path
endpoint-file-name
endpoint-file-path
policy info
policy-name
recipient info
recipient-emailX
recipient-ipX
recipient-urlX
, where X is the unique index to distinguish between mutliple recipients,
sender info
sender-email
sender-ip
sender-port
endpoint-user-name
endpoint-machine-name
server info
server-name
monitor info
monitor-name
monitor-host
monitor-id
status info
incident-status