"NT service\splunkforwarder" does not have native permission levels to read from all the windows log channels, especially the SECURITY log channel and SYSMON channels. The easiest option is to add "NT Service\SplunkForwarder" object to the "Event Log Readers" group in the system. Or create a domain user, restart all the instances of SplunkForwarder service with the newly created domain user and come up with a GPO to add the domain user to "Event Log Readers".
... View more