Has anyone installed the Splunk for Snort app in a 5.0.6 clustered environment? I am curious if the are any caveats for running the app in a clustered environment? Is the app installed only on the search head, or are components also distributed to the indexers?
Thank you,
Matt