hi
please suggest me how can i collect the windows event log without splunk universal forwarder
It requires setting up additional servers, but for most of our Windows events, we use Windows Event Collectors.
https://docs.microsoft.com/en-us/windows/win32/wec/windows-event-collector
Have the data sent to the WEC via subscription, the use a UF on the WEC to send it to Splunk. We had to use this because the Windows Team didn't want additional software on their endpoints.
If you are talking about streaming data rather than monitoring log files then you can set up a TCP input.
https://docs.splunk.com/Documentation/Splunk/latest/Data/Monitornetworkports