Thanks Chaker. I have the STM app installed but I am unable to see any events within it. Would I be using the 'search & reporting' with stream as the sourcetype to view events, specifically to identify events with the details of SMB version in use.
Pardon me for being a noob.
You could use the Splunk Stream App, it supports SMB as a filter.
https://docs.splunk.com/Documentation/StreamApp/8.1.0/DeployStreamApp/ProtocolDetection
The smb.dialect field contains the version.
https://docs.splunk.com/Documentation/StreamApp/8.1.0/DeployStreamApp/FileService