I've seen this on some older posts, but I am currently battling this issue. For some hosts, restarting it makes the logs start flowing again without the above error message (Suggesting a delayed start is the answer). But on some of them, a restart does nothing, there is real security logs that Splunk is merely reporting above error message for.
