/opt/splunk/var/run/searchpeer is filling up the SPLUNK home
This is where the search heads store the bundles that are distributed to peers (indexers). This other answer might be helpful as well: http://answers.splunk.com/answers/111610/