Yes, basically, the steps are the same for event code 4624 (successful login).
Again, it might be necessary to activate the according audit policy for this particular event code.
Also, I forgot to mention that you should to install the "Splunk Add-on for Microsoft Windows" on your search head so that you will get field extractions, etc.
... View more