Identify the Zimbra log data you want to monitor.
Use a Splunk Universal Forwarder to monitor the log files and send the data to your Splunk indexer.
Using the Splunk documentation: Getting Data in
http://docs.splunk.com/Documentation/Splunk/6.3.1/Data/WhatSplunkcanmonitor
to assist in in properly source-typing the ingested data ensuring for proper time-stamping and event breaking.