This generally indicates that load balancing on your forwarders is not optimal.
You can set the forwarders to use time or data based load balancing, and when you see this type of unbalanced behavior you should adjust.
Forwarders will switch indexers based on time or data. In a busy cluster, it is good practice to use time vs data (seconds vs MB's e.g.).
This way, the forwarders will pick a new indexer every 30 seconds, or whatever you pick, rather than getting "stuck" on one indexer based on MB's/data.
https://docs.splunk.com/Documentation/Splunk/8.0.2/Forwarding/Setuploadbalancingd
... View more