It can be due to number of reasons. If you have ensured that MX has correct configuration and should send event to Splunk, I would suggest to try and localize the problem to see whether it is due to MX, Splunk server or network. It can be done by capturing this traffic on MX interface by tcpdump utility to the pcap file and analyzing it. If you find specific syslog message in pcap file, it means the MX sends it and need to focus on Splunk server side or network. You can open case to On-Prem Support and we can do this investigation for you.
BR,
Marat Makhlin
On-Prem Support Teach Lead.
------------------------------
MaratMakhlin
------------------------------