When we test with the splunk forwarder running plus WMI event alert configured, we only get the event either being sent to WMI or to Splunk not for both. So it would seem the wmi provider implementation in CA does not support multiple clients.
If splunk picks up the WMI event, then I do not see it in wmi.
This is only related to Splunk as it tested out fine with Syslog and a WMI alert.
Defect ID: 565770 Not receiving WMI alerts if Splunk subscription is enabled