I was able to resolve this error just now. Go to settings -> lookups -> lookup table files, change the App context dropdown to "All", and search for windows_event_descriptions. It will show you the path of the file, mine is:
C:\Program Files\Splunk\etc\apps\splunk_app_windows_infrastructure\lookups\windows_event_descriptions.csv
-- and when I looked in this folder, the file was indeed missing.
I went to splunkbase, downloaded the Splunk App For windows Infrastructure app, and unpacked the .TGZ manually. The windows_event_descriptions.csv file is contained inside here, I copied it into the above-mentioned folder, and done - no more errors on search. I found more files in here than were in the lookups folder on the system, so I actually copied all 30 of the csv's from the archive, overwriting any already present.
Somehow during my splunk upgrades and splunk app for windows infrastructure upgrades, this file got lost. My splunk app manager showed app for windows infrastructure as being up-to-date.
¯\_(ツ)_/¯ Whatever, I'm happy I got mine to work and I hope this helps you.
... View more