This answer assumes that Splunk is running on the same machine as the Windows log files. I believe the intent of the question was how to index *.evtx files that have been exported from a machine as files and then import them into a different machine running Splunk.
I would like to know an answer to this question as well. Having a similar problem - I upload the evtx file, file recognized by Splunk as preprocess-winevt , complete the import but no data is indexed by Splunk, or very old events (e.g. events from November 2016) are indexed.
Any help is much appreciated, Andy
... View more