In order to get ASM logs you need to configure a logging profile which sends ASM logs to the remotes source. Syslog works for Splunk.
I am sure you got an answer long back but the answer might help someone who stumbles upon this question.
Anyone found any answer to this question. I am struggling to get this app working. But all efforts go in vain. I am also getting the same traffic that charlestips is getting. But not the real traffic. Please help.
There are three Splunk Apps available for BIG-IP. Each of them contain an instructions page for setting up the logs to be sent to Splunk from BIG-IP.
Splunk for F5 Networks
Includes views and reports for the AFM modules, Basic System messages, and Web Stats via an iRule for Virtual Servers with an HTTP Profile assigned.
The logs for AFM are configured using the High Speed Logging feature with a Log Destination and a Log Publisher assigned to a Log Profile.
More information found HERE on askF5.com
Splunk for F5 Security
This app contains views and reports for ASM and AVR module(s) logs. The setup instructions is a PDF file included with the App. tar. The file is named Creating-a-logging-profile-for-Splunk.pdf
Splunk for F5 Access
This app contains views and reports for the APM module logs. The instruction for configuring the BIG-IP logging can be found HERE on F5.com