It's easy to ingest a file, does Splunk know how to parse various SMF record types ?
Is there a free dashboard to report on SMF ?
i think that you would have to use a third party tool (the only way ive seen it work) but i might be wrong.
maybe the following links can help:
https://conf.splunk.com/files/2016/slides/splunking-your-zos-mainframe.pdf (this one is around Syncsort product)
https://answers.splunk.com/answers/88172/getting-data-from-mainframe-system.html (very good answer in the same topic)
https://www.splunk.com/blog/2017/08/22/insane-in-the-mainframe-splunk-and-ibm-partner-to-provide-end... (IBM product)
hope it helps