I installed the Universal Forwarder using the MSI, specified server info, but didn't check any boxes for wineventlog and such. I can see the PC checking in on the Splunk server, but it's not receiving any data. This is my ...\etc\system\local\inputs.conf
[default]
host = PBDC-LT-16
[WinEventLog:System]
interval=60
index=wineventlog
disabled=0
[WinEventLog:Security]
interval=60
index=wineventlog
disabled=0
[WinEventLog:Application]
interval=60
index=wineventlog
disabled=0
Here's a similar situation on Answers that might help resolve your issue:
https://answers.splunk.com/answers/98072/not-receiving-data-from-windows-forwarder.html
In particular "Have you opened the port on your Splunk indexer to receive data from the forwarder? I would try doing a tcpdump/netstat to see if data is leaving the Windows box and/or being received on the Splunk Indexer."