I am not sure I understand your question. If you don't understand the basic tiers of a Splunk deployment and what the function of each of them is (forwarder, indexer, search head), then you should learn that before you try to install an add-on, especially in a distributed deployment.
You have to install the add-on onto your indexers that are receiving data from your Linux hosts.
You have to install the add-on onto your search heads so you can search the indexed data.
You have to install a universal forwarder and the add-on onto each of your Linux hosts, so they can send the data to the indexer.
... View more