There is some overlap in things Splunk and osquery do, when you consider splunk add-ons such as the TA-unix. Like process monitoring, service status etc. they can also compliment each other. You can selectively schedule osquery packs to write results to files that can be indexed by splunk. Osquery is more of a end point security tool, but with the right, add-ons and scripted inputs splunk can achieve the same.