Getting Data In

What is the difference between installing an add-on at the search head and the indexer?

borja_luaces
New Member

Hi all,

I was going to install the Linux Secure Technology Add-On and the installation says that it needs to be installed at the search head.

It might be a simple question but, was wondering, what is the difference between installing the add-on in the search head and the indexer?

Regards

0 Karma

woodcock
Esteemed Legend

This is a very difficult question to answer definitively but thankfully there is a short-hand rule-of-thumb that is easy and almost always works. Install any *-On for * app everywhere (except UFs) and isntall any * App for * on your Search Head(s). Yes, it is that simple.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...