Hi,
The add-on contains configurations that are used both at index time (Parsing/Merging pipelines) and at search time, so you need to install it on the Heavy Forwarders and on the Search Heads.
Basically, what you need to do is to install the add-on all relevant Splunk instances (see above) and either:
Modify the relevant inputs.conf on the Heavy Forwarder to set sourcetype for CEF logs collected by the HF to cefevents or
copy the props.conf supplied with the add-on to $SPLUNK_HOME/etc/apps/cefutil/local and modify the stanza name to match your sourcetype or source.
BR
--Igor
... View more