I want to installsplunk app for zscaler in a distributed environment.
I have search head, indexer and forwarders.
when i install splunk app for zscaler on search head, zscalerlogs index is created on the search head. so that i can't index zscaler log on the indexer.
i want Splunk app for zscaler on my search head, and the index on my indexer. So that , i don't have to index zscaler log on my search head, but i can make search with the app on my search head.
what are the best practices to install splunk app for zscaler in a distributed environment ??