We're seeing a lot of this after this month's Windows update. Restarting the Splunk forwarder appears to have fixed it, We also changed the service start to "delayed".
See: https://answers.splunk.com/answers/200924/formatmessage-error-appears-in-indexed-message-for.html
... View more
Hi @pcordel - Is this a working solution that solved your question? If yes, please don't forget to resolve this post by clicking "Accept" below your answer. Thanks.
... View more