Try using SourceName instead of source:

For each $event in GetObject("winmgmts:{impersonationLevel=impersonate}!//$COMPUTER").ExecQuery("Select * From Win32_NTLogEvent Where SourceName = 'ntbackup'")