@Hitesh Chaudhary , I did as you said, and disabled "Retention method for security log" in GPO. It seems your solution works, but I wouldn't really call it a solution... kind of defeats the purpose of "Group Policy..."
With GPO "Retention method for security log" disabled, reboots revert the setting to "Overwrite events as needed (oldest events first)", however, interestingly, gpupdate /force doesn't change the setting, only rebooting the workstation does (but perhaps this is due to the nature of event logs and maybe it only sets the event log policy once on boot/login, etc).
Having said all that, I am reverting my GPO settings back to their original settings. I shouldn't have to change GPO to align with an obvious bug... smh...