The error message was manifesting itself in the full splunk.
On the indexer/receiver I deleted the files as requested it made no difference.
I changed the two services to run as interactive desktop enabled LocalService and restarted splunk, same messages.
I checked permissions on the folder(s) and added my domain and localsevice both as Full control, restarted, same messages.
I uninstalled Splunk, cleaned the registry using CCLeaner, rebooted, reinstalled using Local account (default setting) and it seems OK now.
Not getting anything from my forwarders still but that is a different question.
... View more