I have some Windows clients and servers.
They have Sysmon, and log are sent with Winlogbeat to Logstash, then Logstash send it to Graylog with GELF type.
1 system / Inputs
2 Manage extractors (on your input)
3 Get start
4 Load messages (an example of your logs)
5 On the part of you need click “Select extractor type” -> Regular Expression