Bigip is set to send to splunk using the remote-server config item using tmm...
After I posted I found a pointer which suggested running tcpdump, and that's confirmed that the packets are indeed being sent to the splunk server.
This then indicated a splunk issue...
Having googled a bit more, I found that the suggested solution is to use syslog-ng to receive the events, and log them out to a file that splunk can then monitor...
So having done that, i'm now getting logs coming through into splunk...
Cheers for pointers...
Regards
Gavin