Windows Event Logs - Import existing logs
I'm not aware of any easy way to extract the logs into the proper format for injection back into enVision.
Obviously if you are using an agent (Snare or EventReporter) then you can configure those agents accordingly. However I will point out that enVision treats these as seperate devices. So if you start with say Snare and then move to the agentless collector, you will see two devices listed for the same system.
I will raise this idea with development team that's working on the new Windows event collector service to see if they can make this a configurable option within the gui.