Correct. You can't install two instances of the agent on a single system, say one for the system and one for the cluster.
I guess how you deploy and configure ossec depends on what it is you want to monitor. If you're watching log files, then you'll have to install the agent so it can see those files no matter which system they're coming from. Are the logs aggregated across the cluster, or kept individually? Look at those factors. - Dave
