Hi @splunk_noob2022 , In terms of "when to restart" Splunk, please have a look at the following docs link: https://docs.splunk.com/Documentation/Splunk/9.0.2/Admin/Configurationfilechangesthatrequirerestart#When_to_restart_splunkd When you make changes to various config files, refer to the link above to confirm whether a restart is needed. Eventually, you'll memorize what needs restarts and what doesn't. For search time extractions, there's not need to deploy the configs on the indexers since the search heads already share those configs in the knowledge bundle. So search time extractions should go on search heads only. For index-time extractions, deploy them on all "indexer" nodes that the data traverses. Since HFs cook (process) the data, you will need to have the TAs on any HF that the data uses. If you're unsure of the data path, it's best to have the index time TAs on HFs and IDXs. I hope this helps! Cheers, David
... View more