Question - I have 3 node linux index cluster and linux cm
we have the Splunk_TA_nix in master_apps on linux cm and it is pushed to indexers ... but i also notice that the previous installer also had the splunk_TA_nix in the /etc/apps dir on each indexer - wasn't getting updated as obviously the newer version goes into slave_apps from CM push
If i want the linux os logs from indexers themselves - do I need the app in both places or can I remove the /etc/apps/ copy
second question - is the best practice to just deploy the TA_nix to the forwarders and then it is not needed under slave_apps on indexer or what is the recommended practice... this TA has scripts that need to run on endpoint so i believe it needs to be deployed to all linux UF's