This answer does not work for me because that directory ( C:\Program Files\Splunk\var\lib\splunk\persistentstorage\WinEventLog ) does not exist and there are no files with "_checkpoint" in the file system except for wmi_checkpoint. And deleting that file and restarting Splunk does not seem to get the job done.
... View more