Splunk is reporting a majority of my windows events are being returned with "Null" in the message field. However, When I review the same message on the server on which the message occurred, there is information in the eventdata field.
Figured it out.. Needed to restart SplunkD to establish new connection to windows servers.
Could also restart WMI service on the windows servers to reset the WMI connection
I think this is related to this bug:
The Message field is not extracted and is therefore missing from imported Windows event log file (.evt) data. (SPL-24947) (the list of known issues are located here)
From what I understand that this is a troublesome bug which resides mostly on Microsoft's side.