Are you also noticing the following messages in your splunkd.log along with the enqueuing very large file message?
INFO TailingProcessor - Could not send data to output queue (parsingQueue), retrying...
Also, what is your maxKBps settings in limits.conf on the Forwarder where you see this message? By default it is
$SPLUNK_HOME/etc/system/default/limits.conf
[thruput]
maxKBps=256
you can try increasing to 512 (double than default) or 0 (unlimited) in $SPLUNK_HOME/etc/system/local/limits.conf
[thruput]
maxKBps=512
Check out this article:
https://docs.splunk.com/Documentation/Splunk/7.2.0/Troubleshooting/Troubleshootingeventsindexingdelay#Possible_thruput_limits
... View more