Splunk Integration Issues

We are facing issues with Splunk Integration for Rancher. We have the HEC token created and we are able to successfully run the curl statement against our splunk endpoint as mentioned in the document https://rancher.com/docs/rancher/v2.x/en/tools/logging/splunk/
Our container logs are getting generated and aggregated at /var/log/containers on the worker node. Our Rancher server is running on a different node other than the worker node. So when the integration to splunk is configured via the UI ( which is getting successfully saved in our case), does the logs get shipped from the node running worker or the node running the rancher server (we run a standalone rancher container).