I know this is old, but for the benefits of future generations: This is caused by the "*_last_timestamp_*.duosecurity" files being blank. This can happen if you run out of disk space, for example. Duo is trying to read a timestamp form these files, getting a null instead, and attempting to treat it like a number. The fix is to simply delete all of the "*.duosecurity" files form "$SPLUNK_HOME/etc/apps/duo_splunkapp/bin" and restart Splunk. The app will recreate these files with proper timestamps.
... View more