Ingestion and normalisation
Windows Security Event Logs — specifically Event ID 4625, failed logon — ingested into Splunk Enterprise and normalised so that source host, account name, and timestamp could be queried consistently rather than parsed by hand each time.