Hi @Neel Darji
Thanks for reaching out to Microsoft Q&A.
By default, you can export Entra ID logs to Log Analytics (Azure Monitor), a storage account, event hub or a partner solution. PIM related logs are located inside Audit Logs.
Depending on the amount of data you want to export, usually, these data are sent to Log Analytics and then other tools, like Splunk, pulls the logs from there.
We do not have any documentation from Microsoft on exporting data to an specific tool, but I found a somewhat old procedure from Splunk that might give you some hints on how to do that. However, I'd recommend you reach out to Splunk support to validate if that documentation is accurate
About your second question, if you already export Entra ID audit logs to Splunk, no further action is required as those logs are part of the Audit Logs.
Let me know if you have any questions.
Thanks,
Fabio