You should be able to set a syslog source from the sidewinder console.
Monitor > Firewall Reporter /syslog
use the export audit to syslog section at the bottom
click the plus
enter the ip address and facility (not sure it matters)
enable and save.
you will see events hitting your splunk server, just make sure to define a UDP input on port 514 and then set the sourcetype of the logs to something that is meaningful if you have other sources using that indexer or input.
https://kc.mcafee.com/resources/sites/MCAFEE/content/live/PRODUCT_DOCUMENTATION/21000/PD21665/en_US/fe_70102_rn_a.pdf
... View more