Thanks Null,
Yes, the policies are the same. We are using WinCollect on a member server to pull logs from the Domain Controllers. After digging a bit in the directories of the Wincollect server we found these entries:
2014-04-29 02:29:01,166 WARN Device.WindowsLog.EventLog.10.10.X.10.Security.Read : Reopening event log due to falling too far behind (approx 138301 logs skipped).
2014-04-29 02:35:37,876 WARN Device.WindowsLog.EventLog.10.10.X.10.Security.Read : Reopening event log due to falling too far behind (approx 208935 logs skipped).
Lots and Lots of them. We found a few similar complaints online and realized that we are backleveled a bit in the WinCollect Code. We're going to upgrade and try from a different box.
Thanks,
Justin