How to receive log, forwarded by SPLUNK?
It depends on how you can send/get it from splunk. Syslog, file or ODBC?
Once you figure out your method, then you need to get a copy of the log data into envision, using the method chosen.
Then you have to use Event Source Integrator to build out your cutom XML for your logs from splunk, which likely do not match what came from the original device (if that is the intent).
ESI can work well. We've used it ourselves to validate/design our custom efforts. But it is not a trivial effort, it takes a bit to figure out. Read the documentation for it.