We have an indexer clustering Splunk environment, and recently, all our indexers are consuming 100% CPU. Not sure what will be the issue.
Are you using Real-Time searches? This will totally lock 1 core on every server.
Have you recently started Accelerating searches? The Indexer CPU cost can add up very quickly and has a temporary "backfill" cost that is very noticeable.
See these links