Will the Qualys VM App for Splunk Enterprise run on a search head cluster?
I don't see anything in the documentation about it. I know some of the third party apps we've used haven't supported running on a search head cluster and we've had to install them on a standalone.
Yes, install the TA on all the search heads in the cluster and enable knowledgebase on them. On your indexer or heavy forwarder install the TA and enable hostdetection and/or was_detection on it. The knowledgebase is a lookup table and needs to be on every search head you search from. Then you can install the Qualys VM App for SPLunk where you need it.
Yes. VM App should be installed on each of the search heads to be able to fetch reports on data indexed on the indexer.