you can add Custom Field (ESM Properties\Custom Types) and then add new parser rule, that will use this field. But in this case (events from the ePO), I think you should to create a new Product Enhancment Request, to change standard rule by the McAfee developers (https://mcafee.acceptondemand.com).
Most rules have a mapping from other vendors to ESM's own severity system. You can see that when viewing ASP rules in the Policy Editor.
Basically, there is a mapping so that for example, vendor-1 will map Low to 25, Med to 50, High to 75
While for another vendor, it may map 1 to 10, 2 to 20, etc.
Looks like in this case ePO's value of 6 is mapped to 61 in the ESM. Possibly because severity starts at 1.
I beleive artek to be correct as far as the parser rule.
However, with the level of integration between the two products, I think that more so the idea of the product enhancement to be the way to go in the long term.