From the atp-splunk_connector.log you see the following error:
Upload failed with httpcode: , status code: , Reason: [Server is busy]
This can be caused by overloading the Splunk indexer.
This can be resolved on the Splunk side by switching from a single Splunk data collection node to a distributed deployment configuration.
It is possible the issue is different, in which case we recommend referring to Article Id: 215022 if necessary. This article titled EDR stops sending events to Splunk https://knowledge.broadcom.com/external/article/215022 refers to an issue where the time range trying to be collected may be too large and EDR may be purging the data before it can be forwarded to Splunk.