All Apps and Add-ons

Simple install question

cboillot
Contributor

I am running in a distributed environment. Where do I install this? Search head? Indexers? Both?

Tags (1)
0 Karma
1 Solution

HiroshiSatoh
Champion

Either one is fine. However, if there are multiple indexers, the log is output only to the index of the installed indexer.

For the search head, if the output.conf setting is included, it is output to the indexer. If there is no setting, it is output to the search head.

View solution in original post

0 Karma

HiroshiSatoh
Champion

Either one is fine. However, if there are multiple indexers, the log is output only to the index of the installed indexer.

For the search head, if the output.conf setting is included, it is output to the indexer. If there is no setting, it is output to the search head.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...