SIEM not ingesting Windows logs from servers

Hello,

I've been testing the new SIEM function, I've got 2 domain controllers/servers sending through logs via Winlogbeat and 4 client PCs sending logs again through the same method. When I check via dashboards or even just the 'winlogbeat*' stream, I am seeing all the information. On the SIEM however, it is not picking up the events from the servers/domain controllers. Just the logs from the 4 client PCs. Is there a way to get the SIEM function to recognize this?