So there does appear to be indexing errors. illegal argument exception total fields reached we fixed this before I will go back through our tech volumes and see what was done.
Usually Windows logs ingested in Graylog are in JSON/GELF format with an automatic JSON/GELF extractor so it creates many fields. The best way to handle this is to put Windows logs in a dedicated index. Moreover you can increase the limit of 1000 fields (1500 or 2000 should be fine).