Sure. You can have Splunk forward on anything it indexes via syslog format. Generally, you configure the indexers to forward on syslog, not the forwarders. The thing to note is that Splunk's Windows Event Logs will have internal newline characters. It shouldn't cause any problems with receiving syslog agents, depending what they do with it though. I would nevertheless have you test it against your preferred receiver to see if you like the results.
http://www.splunk.com/base/Documentation/latest/Admin/Forwarddatatothird-partysystems#Forward_syslog_data
... View more