Getting Data In

What is the difference between installing an add-on at the search head and the indexer?

borja_luaces
New Member

Hi all,

I was going to install the Linux Secure Technology Add-On and the installation says that it needs to be installed at the search head.

It might be a simple question but, was wondering, what is the difference between installing the add-on in the search head and the indexer?

Regards

0 Karma

woodcock
Esteemed Legend

This is a very difficult question to answer definitively but thankfully there is a short-hand rule-of-thumb that is easy and almost always works. Install any *-On for * app everywhere (except UFs) and isntall any * App for * on your Search Head(s). Yes, it is that simple.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Laser Bananas and Edge Hubs: Exploring Operational Technology (OT) Data Through a ...

  OT is a different environment to traditional IT and can have interesting challenges when interfacing the ...

Event Series: Mastering AI Tokenomics and Splunk Agent Observability

Beyond the Black Box: Correlating AI Performance and Tokenomics with Splunk Agent Observability   As ...