1. My network security device (F5 WAF) sending syslog/events logs to siem tool(splunk) then what kind of forwarder will my network security device?
2. Can we purse payload on splunk receiving events get from WAF and how?
It's not clear what you are asking. Please re-phrase your questions.
Be sure to check splunkbase for apps that can help receive events from your WAF device.