Yahmza, did you manage to find an answer to your question elsewhere? I am considering the use of Splunk within my environment and integration with EnVision would be key.
Events within RSA enVision can output directly to a flat file by way of the “lsdata” command. Based on specific criteria passed with the lsdata command, events collected are presented in a syslog formatted log file.
Example: lsdata –events syslog –time start now >> log.unx
After that you can have these files be picked up by Splunk UF/HF and forward them to your Splunk index.