Yes, the specific indexer is getting this issue for one of the following reasons:
1 - the indexer should be connected as a slave to a license master in your environment, but it is not.
2 - the indexer does not have a current license installed.
3 - the indexer has exceeded its daily indexing quota too many times in the last 30 days.
If you log onto the indexer as an admin, you can see (and change) the license information under Settings>>Licensing
In the Splunk Administration manual, there is a section on configuring Splunk licenses. The manual also explains how license violations work. You may need to contact Splunk Support to unlock the search functionality.