Do I need to break out parts of the configs to install on an HF or indexing cluster?
Will TA-threatconnect run on a search head cluster?
From what I can tell it is described in the documents as being installed either on a search head cluster only or on a stand-alone-all-in one Splunk instance[did I miss something?].
Splunk 7; ThreatConnect TA-threatconnect 3.1.5