I had an issue with this at fist.
Ensure that you have the following configured on your Cisco devices:
logging trap (trap level)
logging host (Splunk Server) transport (tcp | udp) port (514)
logging on
In Splunk's Data Inputs:
Add a TCP or UDP type (I use TCP) and ensure that it's setup for 514 and the sourcetype is syslog
After that, I'd check to see if you have a firewall blocking port 514 (or whatever you're using) to your Splunk server.
... View more