It will depend on your data-sources. Do you already have DLP data, such as McAfee DLP? If so, you could simply push your DLP events from ePO to the SIEM.
And then get inspired by the DLP dashboards provided in ePO to replicate them into ESM, where you create alerts.
Thanks for your response, however i want to create that the rule in epo not in SIEM.