Same error happened.
I was able to overcome this by creating file /opt/splunk/etc/system/local/audit.conf with the following content:
[auditTrail]
privateKey = /opt/splunk/etc/auth/audit/private.pem
publicKey = /opt/splunk/etc/auth/audit/public.pem
... View more