I have, quite extensively, used HTTP Event Collector to get IoT data into Splunk. Many IoT services will allow you to set up an API connection. If the service can do HTTP POST, then no problem, just point it at <your-splunk-instance>:8088/services/collector/raw with header "Authorization: Splunk <token>". If the service requires HTTP GET, you could use this REST API addon from Splunkbase (https://splunkbase.splunk.com/app/1546/), or you could build your own with addon-builder (https://splunkbase.splunk.com/app/2962/), or you can do what I usually do, which is to set up a logic app in Azure, to handle all the API calls. (https://docs.microsoft.com/en-us/azure/logic-apps/) Anyways, getting IoT data into Splunk should be easy.
... View more