Install TA on SH only or both SH and HF ?

Hi. Would I install the TA for fail2ban on just the search head or on the heavy forwarder also?

That depends on whether the TA contains only search time configuration (e.g. field extractions), or also index time configuration (e.g. timestamping, linebreaking...).

Since this TA includes linebreaking and timestamping config, you need to put it on the HF as well.

