Hi,
You should read the following section of the docs:
And then you should read:
http://docs.splunk.com/Documentation/Splunk/4.3.1/Data/MonitorFilesandDirectories
Fairly simple file monitor really... You will just have to make sure that you are reading the files using a Windows based Splunk instance, as it will need to access the Windows binaries for reading the EVT/EVTX files.
Hope this helps answer your question.