thinking back on this, it's not a terrible idea. Having a single secure data stream "catcher" interface to your core can have it's benefits. If your CDR machine goes down, the data isn't lost forever. The security aspects make it a single box to deal with. If Splunk's job is to sit between two applications - like your PBX and CDR, and it adds some level of benefit either in security and/or reliability, then why not?
But the more i google on Splunk, the more I see it can A) bind to a port and catch stuff, so your Splunk guys should be easily able to tell you that and B) there's a company called sideviewapps that have Cisco Call Manager reporting tools to install atop your Splunk.
So, if they want a single secure man in the middle for your CDR, it'll probably work easily. If they want the same graphs they saw Cisco can do, then probably not.