Splunk will show a sourcetype of preprocess-winevt on the preview screen while giving you the raw file output. This is normal. Click through all the rest of the adding data prompts and then splunk will send the files through the correct processor to index the events
... View more