There are two windows event log views (provided by microsoft, independent of splunk):
- The General Tab (everything is in "human language", datetime stamp doesnt have ms)
- The XML View (everything is in "machine language" (XML), datetimestampe DOES have ms)
Those details you speak of are in the XML view but you're not using
RenderXML = True to see the XML view. Therefore, you're not seeing the milliseconds. WARNING: if you switch to XML view, you'll find other behavior you wont like.
Finally, if this makes you upset make sure you blame M$ not Splunk because Splunk has nothing to do with M$ coding. Well... they did setup shop in washington just to leech talent from M$ so technically some of the Splunk developers might have something to do with event viewer code, but XML vs Human view has been around since pre Windows 2000. So it would be a SR Dev / Architect you'd probably want to blame instead of Splunk as a whole.