I am not sure which Splunk ES related apps go where.
My deployment looks like the following:
Splunk universal forwarder (windows/linux/) + syslog ===> 2 Heavy Forwarders =====> 2 Indexers ======> 1 search head/master
I deployed the OS related TA app on the UF and the ES app config on the search head/mater. I am not sure where any of the SA or DA files need to go in addition to this.
Do i need to copy the app files into the indexers as well?
ES should be on a dedicated search head. It's too demanding of resources to share a box with adhoc searches and cluster master.
Yes, TAs need to be installed on the indexers.