Hello per the documentation on the developer website:
"The webhook functionality is built into Splunk Enterprise as an app, and is located here: $SPLUNK_HOME/etc/apps/alert_webhook. If you are so inclined, you can clone it, and then modify it however you want. For example, you might choose to do this if your application accepts a specific payload that does not match to the Splunk Enterprise default."
http://dev.splunk.com/view/dev-guide/SP-CAAAE7A
... View more
As usually it depends. If those apps have any views/dashboards then those are installed on sh layer. Usually “apps” (aka TAs) w/o views are installed mainly on heavy forwarded (some time UF or IDX), but I think that there are also times when those are also installed on sh-layer too (e.g. fields definitions),
... View more