Usually splunk seems to interpret hypens for event viewer as folders. I have this input but its not working.
[WinEventLog://Microsoft-ServerManagementExperience
disabled = 0
index = wineventlog
Here is a screenshot of the folder i'd like to monitor with Splunk.