Solution found myself. It's caused by permissions issues. There's an inputs conf file which won't allow changes to be made to it.
Here's the solution...
Copied input Conf file to desktop from:
C:\Program Files\Splunk\etc\deployment-apps\TA-microsoft-windefender\default\inputs.conf
Opened on the desktop with notepad:
[WinEventLog://Microsoft-Windows-Windows Defender/Operational]
index = windefender
disabled = true
renderXml = 1
Changed disabeld = true to disabled = 0
Saved as a conf file and pasted over the existing conf file overwriting it.
Windows defender event log now says enabled.
... View more