Have a look at the Cloud Security information on the Australian Signals Directorate's website.
Here are some things that we recommend for hardening your Splunk environment.
http://docs.splunk.com/Documentation/Splunk/latest/Security/Hardeningstandards