I figured it out. The solution is to add a section and stanza in the inputs.conf file on UF-end.
[WinEventLogs: Kaspersky Event Logs]
disabled = 0
start_from = oldest
Then, restart the SplunkForwarder Service.
Cheers. Mitesh.
Kaspersky stores data in ms sql. From there, you can take data.