Kate,
When you say "I have a Juniper firewall that forwards syslog/udp:514 data from a forwarder", are you using a full forwarder? If so, then you will need to deploy TA-Juniper at the forwarder. I recognize that this would not explain why one indexer is working and the other is not but may be contributing to the problem.
If this is not the case, could you please open a ticket with support and provide diags? This will make it much easier for Splunk to get a handle on the root cause.
... View more