UCP audit logs to Splunk


What is the easiest way to get the audit logs from UCP to Splunk? I thought that changing the ucp-controllers configurations would solve this issue, but those can’t be changed from UCP GUI services because it’s not seen in there although Show system resources is enabled. Any ideas what the best or easiest solution would be to get the audit logs to Splunk?