We are new to Splunk Cloud and have a question about installing app/add-ons that we couldn't find definitive information on in the documentation.
We have 3 instances, IDM, Search head 1, and Search head 2 which is our Enterprise Security (ES) instance.
Which one is the indexer? The IDM instance is a sort of Heavy forwarder correct?
When installing apps such as the 'Splunk Add-on for F5 BIG-IP' or the 'Cloudflare App for Splunk' the instructions say to install on the search head(s), Should they be installed on Both search heads? Or just one? What are the advantages or disadvantages of either?
Sorry for the barrage of questions but we are having trouble wrapping our head around how these instances all work together and how the apps interact. Thanks!