I just had a case with the exact error. It turned out to be related to Splunk's inability to process the data due to some issue in the data.
In the case I worked on, there were base64 VALUES that had a hidden character at the beginning.
I am aware of one other case, which had unusual (not UTF-8) characters in the data.
Solution:
Fix your data. Examine it with a programming Tool (I use MacVIM, and GVIM). You may not see the problem when just looking at the logs.
If you can't fix your data prior to ingestion, what you can do is go into the search.log, determine which search (or source) is generating the problem and disable it. I realize this is a temporary solution, but it is a workaround until you can clean up your data.
I was not able to find any "Splunk Bugs" on this particular issue, possibly because it falls more under "quality of incoming data".
... View more