Hi @sswigart
I think you should be able to setup a monitor in inputs.conf but using the "preprocess-winevt" sourcetype, although I havent done this for some time.
#inputs.conf
[monitor://Path/To/Your/security.evxt]
index=yourNewIndex
sourcetype=preprocess-winevt
Also check out https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Log-evtx-file-import-Foriegn-AD-Domain...for more info on this approach.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing.