The standard table reader can be used to read from a table with specific specific critera and specific fields sent to Splunk.
Open the Administrator -> Metric Filter -> SM37 job filter
Add in a jobname (wildcards are supported, ‘*’ means all jobs) and check either
IsFinished – All finished jobs that match the JobName filter have their logs sent to Splunk
IsCanceled – All cancelled jobs that match the Jobname filter have their logs sent to Splunk