The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
It analyzes the entries in the "wineventlog" index (used by the Universal Forwarder). If not data is displayed, please verify that the Universal Forwarder is installed properly and that the all the Windows event logs are sent to the "wineventlog" index.
Send any suggestions and questions to firstname.lastname@example.org. We can also provide advice in setting up the Splunk receiver for the Universal Forwarder.