OK, I'm running Splunk Light on windows, using the Universal Forwarders, NOT using Deployment server setting, but the Index Forwarder setting.
So my problem was the fact that the Splunk Light be Default, only searches the Main and OS Indexes. Me being New to Splunk, this was very frustrating as i didn't know that.
Once you enable the Windows Addon (which you need) it creates a wineventlog index. All of the data from windows goes into those indexes (Application, System, Security only).
The only way to get this data to show, would be to search using "index=* host=bla" to see the data i was expecting to see.
I created a "authorize.conf" under Splunk/etc/system/local/ and added this to the file:
[role_admin]
srchIndexesDefault = *
restarted Splunk Light.
Now everything shows up by default, and all my hosts show up with the correct information.
Not sure if this is your issue, but i wanted to share mine since they were "similar"
... View more