We are trying to use splunk to log our Isilon SMB activity. However it does not seem like the TA for CEE server will run on Windows and CEE server is only available for Windows? Are there any alternative ways folks have successfully logged this information to splunk ie syslog?
Have you tried using the Splunk App for Stream? You could configure it on the server that mounts the directories, and specifically monitor any port and protocol required. Events will be collected from the wire and logged as JSON events into Splunk.