Hi,
Let say that your Syslog to Alarm name is "recover err-disabled". Then you can use it on Policy Center.
Add an event and select Alarms: "Trap upgraded from syslog" <-- that is the actual name.
Then on the "Alarm Variable Matching Rules" section add the following:
1. Alarm Variable Name: "Rule Name"
2. Regular Expression: "recover err-disabled".
That is the way to trigger syslog to alarm events.