Using Syslog forwarding will work but it is not the best way, as the problem with any syslog (TCP/UDP) is that is target is down messages can be lost. (also suing syslog the mapping won't be good as it won't be correlating events with Deepsight GIN data.
SSIM has special Symantec EndPoint Collector 4.3. This collector goes directly in the DB to collect information (it support SQL or Sybase)
If you are using SSIM 4.6 or 4.7, this collector is alredy pre-installed onboard.