Would anyone happen to know does / can splunk access the syslog data from orion?
Set a rule in the Orion Syslog system to forward all of the logs to the Splunk system. I believe as of v10 you have the option to have the log keep it's original source system details intact as it forwards the logs to your Splunk system.
Where is this done at?