On a Distributed environment of Splunk Enterprise architecture, Where can the REST API Modular input app be installed ?
On the Search Heads only ?
Installation is pretty simple. You just need to copy the files to /Splunk/etc/apps and restart Splunk.