We were able to create a deployment app on our Heavy Forwarder, created a serverclass as well, and customized the inputs.conf to grab the Winevent logs. However, the client stated that they were only receiving general audit information that showed who logged in, etc but didn't receive the actual log information. https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/MonitorWindowseventlogdata#Monitor_Windows_event_log_data_with_Splunk_Cloud_Platform This is the link we used to assist.
... View more