The data from the windows logs was set to 20Mb (not much). As soon as you reach maximum the oldest message gets deleted to let the newest one register. Because of that the beginning of those logs were from 5th of february (one month after election).
Splunk is actually a software that can 'cut' messages into pieces and put them into fields. You can then query those fields. For example if you have log lines like this: 'timestamp source destination username' with each field being potentially different on every lines and you feed everything to splunk you can then ask 'how many different usernames has there been between Xtime and Ytime'. You can of course create much more complex queries.