QuestionQ59

Installation and Configuration

A site has one existing search head that hosts a mixture of CIM-compliant and non-CIM-compliant applications. All applications are mission-critical. The customer wants to manage costs carefully while achieving good ES performance.

What is the best practice for installing ES?

  • A Install ES on the existing search head.
  • B Add a new search head and install ES on it.
  • C Increase the number of CPUs and amount of memory on the search head, then install ES.
  • D Delete the non-CIM-compliant apps from the search head, then install ES.
Explanation

Splunk Enterprise Security should be installed on a dedicated search head or dedicated search head cluster. Only CIM-compatible apps or add-ons, or apps intended to integrate with Enterprise Security, should share that search head; non-CIM-compatible content can prevent ES searches and dashboards that rely on CIM fields from working correctly. A new search head therefore isolates ES while retaining the mission-critical existing applications.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!