I moved from this to a separate question here:
http://answers.splunk.com/questions/4785/windows-event-log-collection-via-microsoft-scom-2007
Basically it looks like if I want all the events in there then I have to use a Splunk install as a forwarder - with the option of making it a Light Forwarder after it's configured.
... View more