Dear SPLUNK Community,
According to the documentation: http://docs.splunk.com/Documentation/UnixAddOn/5.2.0/User/DeploytheSplunkAdd-onforUnixandLinuxinadis...
we need to install the Supporting Add-on (SA-nix) on the Search Head and Indexer clusters.
I have already installed the Splunk Add-on for Unix and Linux on the Search Head and Indexer clusters. And I do forward all data from SHs to indexer cluster.
I would like to know what would happen if I do not install the SA-nix there?
Please see the documentation here as well: http://docs.splunk.com/Documentation/UnixApp/5.0.3/User/DeploytheSplunkAppforUnixandLinuxinadistribu...
SA-Nix supports the visible Unix app. You need it if you're using those dashboards, but you don't need it to work with Unix data directly in your own searches and reports.
View solution in original post
Thank you! that helps.