it's hard to debug a problem likethis!
what Linux are you using? see on internet if there are known issues on this Operative System.
Anyway, I suggest to open a case to Splunk Support because the only way is a webex to see you installation.
i know it's old thread ,i assume it helps ,
once check DMC on your search head , and go to "resource usage: instance"
check for Maximum Physical Memory Usage by Process Class& Maximum CPU Usage by Process Class
identify which process class consuming more resources , usually it is "search activity" in my case