Raj,
The probe help says this about the sysloggtw probe:
The Nimsoft Syslog Gateway is capable of relaying or forwarding incoming syslog messages as well as Nimsoft messages to other syslog deamons.
There is a configuration option for the sysloggtw probe where you can enter remote syslog daemons. The probe help says this about that option:
Lists the Syslogd hosts to which relayed syslog messages of messages from the SYSLOG-OUT queue are sent.
When I start the probe, I can see it subscribes to the hub listening for messages with a subject of SYSLOG-OUT. Because the help mentions a SYSLOG-OUT queue, I suspect the probe tries to connect to a queue named SYSLOG-OUT first and then subscribes to messages with a subject of SYSLOG-OUT if no queue exists.
This should get you what you need. Now you just have to see how the outgoing syslog messages from alarms look and determine if they will meet your needs. If not, you can probably use a Lua script to format the messages and post them rather than letting the AO post them directly.
Let us know how this works for you and how it all interacts with Splunk.
-Keith