EPStack comes with 3 default inputs sources enabled: Lumberjack, Syslog and Windows Event Logs. Simply point your sources to the IP (and port) to your EPStack IP. These ports can be modified via the Admin Panel.
Lumberjack: port 5000
Syslog: port 514 (TCP or UDP)
Event Log: port 3515 (via Nxlog utility)
*Nxlog is capable of forwarding local files as well as event logs which can be used for file based logs such as IIS logs.