you seem to have a double-slash after C:, also not entirely sure of the case sensitiveness of Splunkd on windows, but just in case might want to preserve the case if you can for the entire path.
Ok, working now. In my testing I've found that both ways will work:
[monitor://C:\stuff] and [monitor://C:\\stuff] work. Confirmed by trying both and seeing the source appear in metadata.
Splunk, I might have missed this but it would be useful for you to provide some Windows syntax examples either in spec file or online documentation. Thx.