WORKAROUND:
InTrust does have the capability to 'export' data from the Repository directly to a Splunk DB, however according to Splunk Enterprise 'Getting Data In' documentation, it may be possible to upload the historical data if the data is in native .evt file format.
Please review http://docs.splunk.com/Documentation/Splunk/6.5.1/Data/MonitorFilesandDirectories, for the available options
To convert the historical data from an InTrust Repository to Native .evt file format, please review
Knowledge Article 18825 'Can the Repository files be converted back to .evt, .csv or .txt format?'
https://support.quest.com/intrust/kb/18825
or
Knowledge Article 27372 'How do you export an .EVT file from the InTrust Repository?'
https://support.quest.com/intrust/kb/27372
For complete documentation on the restoring Events in Native Format (ITEventExtractor.exe)
https://support.quest.com/technical-documents/intrust/11.2/understanding-intrust-repositories/repository-tools/restoring-events-in-native-format