Use Splunk add-on for Windows https://splunkbase.splunk.com/app/742/
It has a very good support of plain text as well as xml wineventlog by providing specific field extractions for some logs and provides generic field extractions for other logs.
It also fixes some field extractions issues in auto extracted fields by Splunk from both plain text and xml
My recommendation is to use XML format which seems faster in retrieving from windows and faster search time parsing in Splunk
... View more