Specifically, Quick summary information by host, source, sourcetype and index to locate the cause of the variance.
I presume that you are using auto load balancing on a forwarder, although you have stated that is the case. The sessions are not going to send exactly the same amount of data. It really depends on the type of data being sent. For instance, udp packets are going to be essentially one event per packet. Windows Event logs are not going to be one event per packet because of the way that Splunk uses WQL to query for events. You end up with variations in the size of the data sent to each indexer under that type of a configuration.