I am running in a distributed environment. Where do I install this? Search head? Indexers? Both?
Either one is fine. However, if there are multiple indexers, the log is output only to the index of the installed indexer.
For the search head, if the output.conf setting is included, it is output to the indexer. If there is no setting, it is output to the search head.
Either one is fine. However, if there are multiple indexers, the log is output only to the index of the installed indexer.
For the search head, if the output.conf setting is included, it is output to the indexer. If there is no setting, it is output to the search head.