Where does Splunk universal forwarder actually get the data?
How do it organizes the data and send to Splunk indexer?
Kindly please help along with the file names.
OS: Windows
Please read this and it will give you the details for how to monitor windows events.
http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitorwindowsdata