I have a search head, indexer, and several web servers and run as forwarders. Where do I install this app?
I'd like to see an answer from the author on this as well. It's obvious that a lot of thought has been put into this app since it uses eventtypes, datamodels and kv stores. I would be great if @jbjerke_splunk could add this documentation for the targeting of components to a distributed Splunk environment.
Unarchiving the conf files in this app shows the following configs below. Right away I notice indexes.conf which usually means an index is being defined. For the most part, this means this config should reside on your indexers. It would be helpful to know if the props.conf and transforms.conf (and any other confs) also need to reside on both search head and indexers.
SplunkAppForWebAnalytics/default/savedsearches.conf
SplunkAppForWebAnalytics/default/ui-prefs.conf
SplunkAppForWebAnalytics/default/eventtypes.conf
SplunkAppForWebAnalytics/default/datamodels.conf
SplunkAppForWebAnalytics/default/inputs.conf
SplunkAppForWebAnalytics/default/app.conf
SplunkAppForWebAnalytics/default/indexes.conf
SplunkAppForWebAnalytics/default/transforms.conf
SplunkAppForWebAnalytics/default/collections.conf
SplunkAppForWebAnalytics/default/tags.conf
SplunkAppForWebAnalytics/default/macros.conf
SplunkAppForWebAnalytics/default/props.conf
You can install The Application on Indexer (or) Search head.Based on your Data Traffic you can choose any one.If you don't want to give more load to your Search head then indexer is good.