We have some TA's that we're suspicious are loading data disproportionately and we'd like to know if the indexers have a way to see what percentage of an index is held by the indexer.
Just use top splunk_server
after you search over the index in fast mode:
index=foo | top splunk_server
Documentation here:
The splunk_server field contains the name of the Splunk Enterprise server containing the event. Useful in a distributed Splunk environment.