So we had done all of the above. There are no logs files on the user clients. We have cleaned the database of all log files. All services are off.
When we turn the services back on it works for a moment and then all the logs (that have been deleted on the client) start flooding back in.
Why?
THERE ARE MORE LOGS... (on the clients)
x:\programdata\sccom\txthrlog\tempthreatlog_XX.....XXX.txt
This must be a left over from stopping the clients. There are others logs adjacent to this folder however the above logs clearly captured its data during the issue Saturday morning.
Change the name of this file or delete it. No more flooding.