Hello,
Can you please let know on which Tiers of Splunk enterprise do we install MISP feed Addon. Do we require it to be on both Indexers & Searchhead or just Searchhead is enough?