Couple questions about the Splunk Add-on for Box. We're setting up a heavy forwarder to collect the data. Do we need to also install the add-on on both the Search Heads and Indexers as well, or just the Search Heads?
I'm also trying to determine how much disk space is needed on the heavy forwarder VM. Do the Box logs get stored on the heavy forwarder or do they get passed directly to the Indexers, without a copy being saved?
As for your second question, no, the Box logs are not stored on the heavy forwarder, but they do get parsed there before they are sent on to your indexers. In general, when you think about scaling your forwarders for your data collection tasks, you are considering throughput, not storage. More here: http://docs.splunk.com/Documentation/Splunk/6.3.0/Deploy/Datapipeline
In this case, the Box API has rate limiting, so you are most likely going to be fine with one heavy forwarder.