After installing Splunk Universal forwarder in Windows Server ., how to add monitor stanzas for getting windows application , security, system logs via command line ?
>splunk add monitor
You can only do part of the job using ./splunk add monitor (on a forwarder). You would still need to manually alter inputs.conf to add the index information.
Why wouldn't you add manually on the UF, or use forwarder management on the indexer to push out configs. ?
Failing that, I think you can tick a checkbox when you install the UF on a windows box to specifically forward Windows Event Logs.