Send Falcon detections to Splunk. Do not send the raw endpoint telemetry.
Falcon knows an enormous amount about what every endpoint is doing and it will happily send you all of it. Do that and your Splunk bill doubles, triples or quadruples. Then it gets worse, because Splunk itself crumbles under that kind of ingest, and God forbid you try to search those Falcon logs at that volume. For a large organization the indexes collapse and the data becomes unsearchable, which is the worst outcome available: you are paying for it and you cannot use it. A small shop, fine, that is probably not true for you. Any large one, it is.
I am not going to prove the cost claim, and I do not have to. Do the simple math yourself. Gigs per day ingested against how many log lines Falcon produces from a single endpoint with a real person using it all day. It is mathematically impossible to avoid. If you want proof, hook it up and watch your next monthly bill.
Most customers end up sending alerts only. There is a reason for that.