As alacercogitatus mentioned, you'll want to look at how the heavy-forwarders are connecting to the indexers (every forwarder has every indexer in outputs.conf, there isn't network connectivity issues, etc), but one other thing worth mentioning is that you might have a large amount of excess buckets on the indexers near capacity. These accumulate over time, especially if you are performing maintenance on the indexers, and depending on your rep/search factors. They can be removed periodically to free up space.
See : http://docs.splunk.com/Documentation/Splunk/6.2.3/Indexer/Removeextrabucketcopies
... View more