On the Splunk side , in a Distributed environment, where should this Windows Defender ATP Modular Inputs TA be installed ?
Only on the Search Heads ?

Hi @rajanala ,

It looks like it should be installed on:
A heavy forwarder & search head(s)

It's recommended to put it on a heavy forwarder, where the data will be collected by the modular inputs, and then sent to the indexers. The search heads will need to get a copy for any search-time configurations.

