(Can't find any documentation on this, you'd think it would be linked from the "details" page... but alas.)
Where does the Splunk TA for Suricata get installed in a clustered environment?
In an app to be deployed to the suricata box themselves?
On the searchhead-master?
I just saw this question, it needs to be deployed to the indexers and search heads. Indexers for the linebreaker, search head for the searchtime props.conf, tags.conf.