Splunk knows the record format of QRadar message quite well, so just use the LEEF generator: CKQCLEEF for batch jobs/log file based transfer, or CKQRADAR for real-time transfer of SMF records to Splunk. Specify the tcp name or IP address of the Splunk machine in CKQLEEF/CKQLEEFL.
Using
Google you will find many posts with recipes, but in my experience you just point CKQRADAR to the syslog receiver port for Splunk, and go.
------------------------------
Rob van Hoboken
------------------------------