Have a below setup added to imputs.conf
#MONITOR JAVA LOGS IF THEY EXIST
[monitor://C:\Users\*\AppData\LocalLow\Sun\Java\Deployment\logs\*]
disabled=0
index=winevents_end_user
sourcetype=java
What else do I need to do to get this working and what search do I need to run to get results on this
Make sure Splunk has read access to the files it is to monitor. Check splunkd.log for messages that may indicate why the files are not monitored.
A starting query to look for the results is
index=winevents_end_user sourcetype=java