I am new to Splunk as well, but this is what I did to get NPS event logging into Splunk.
First, NPS was set up to log to SQL. See https://technet.microsoft.com/en-us/library/dd197595%28v=ws.10%29.aspx and other documents on how to do this. (The SQL DB was set up by someone other than me so I can't provide good details)
Second, I installed the Splunk DBConnect application. With that I set up a DB connection to the NPS SQL database, and then defined database input of the type 'tail' with a "Rising Column" of the id field from the database. I didn't specify any special SQL query so I get all events, and I used the 'auto' interval method.
This seems to be working just fine.
... View more