You actually need to have the "Splunk Add-on for Microsoft Windows" installed on your Searcheads/Indexers.
https://splunkbase.splunk.com/app/742/
This will configure all of the necessary field extractions in order to allow those searches to run, and as you have noted formats the data inline with the Splunk Common Information Model
When you install the TA on an indexer/SH you don't need to configure anything, simply install and restart when prompted.
Sidenote: Best practices says that ideally you remove the inputs.conf/eventgen.conf/sample data when installing to Production, but not strictly necessary.
... View more