I faced a similar problem and enabling/ disabling the following policies via GPO sorted the issue out.
- Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\Audit: Shut down system immediately if unable to log security audits
Set the security policy to > disabled - Computer Configuration > Administrative Templates > Windows Component > Event Log Service > Security > Control Event Log Behavior when the log file reaches its maximum size,
Set the security policy to > disabled
- Computer Configuration\Windows Settings\Security Settings\Event Log\Retention method for security log Audit.
Define this policy setting > select overwrite events as needed