Maybe Splunk is monitoring too many files on your forwarder for the OS to handle. You could try increasing the ulimits:
https://docs.splunk.com/Documentation/Splunk/7.3.0/Troubleshooting/ulimitErrors
I would also ensure you didn't accidentally add a directory with a huge volume of files. I'd double check your inputs.conf.
... View more