What .conf files do I change (path?) to add new windows event codes to like 4726 and so on? What Splunk sever is this done on?
Event log filters are defined in inputs.conf and copied to any instance of Splunk running on Windows, typically in %ProgramFiles%\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\local when Splunk Add-on for Microsoft Windows is used. See https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf#Event_Log_filtering.