I am installing Recorded Future Add on App into my Splunk ES environment I would like to know which Search Head should we install the Recorded Future App. Search head 1 (where Enterprise Security is installed) or Search Head 2 where ES is not installed. My better judgement tells me Search Head 2 however what is the Splunk best practice for this?
Hi @sifmad23,
Splunk recommends apps should be installed on other search heads if any. The reason for this is make ES have more available resources. It is better to install on Search Head 2.
Hi @sifmad23,
Splunk recommends apps should be installed on other search heads if any. The reason for this is make ES have more available resources. It is better to install on Search Head 2.