I too am confused as well.
Palo Alto say in the documentation (https://splunk.paloaltonetworks.com/installation.html) that the only the app should be on the search heads.
Important changes
**Previous* guidance was to install the App and Add-on to all Search Heads, Indexers, and Heavy Forwarders. However, this can result in duplicate storage of accelerated datamodels. Now, it is recommended to install the App only on Search Heads per the table above. If you have installed the App on Indexers or Heavy Forwarders, please delete the App so only the Add-on remains on those nodes.
Earlier versions of the App would install the Add-on automatically. This is no longer allowed by Splunk so since App 5.4.2 you are required to install the App and Add-on individually.
Data Model acceleration is no longer enabled by default. Dashboards will not display any data until the data model is accelerated.*
Yet the addon has all the lookup files?
... View more