The reap_time (time to clean up expired search artifacts) is 20995ms. This looks to be on higher side. Again this value is subjective to the setup.
This means you have more searches running at that time.
check for cpu and memory utilization for this SH at the same time.
Search > Activity > Instance shows the top 20 memory searches and nothing stands out.
Under Resource Usage: Instance, the graph shows us that **search** took 10 GBs of memory just before the crash and the **splunkd** process took over 20 GBs of memory. What can it be?