You won't need any iRules to log out to a Splunk server from ASM, what you will need to do is configure a Remote Logging Profile with the relevant options and assign it to your ASM Web Application. There are some sections in the relevant Configuration Guides for ASM which describe this:
For v9.4.5-9.4.8:
https://support.f5.com/kb/en-us/products/big-ip_asm/manuals/product/asm_945_config_guide/asm_sys_mgmt.html1028448
For v10.x:
https://support.f5.com/kb/en-us/products/big-ip_asm/manuals/product/asm_config_10/asm_sys_mgmt.html1028448
Aaron