QuestionQ67

ES Deployment

Where should an ES search head be installed?

  • A On a Splunk server with top level visibility.
  • B On any Splunk server.
  • C On a server with a new install of Splunk.
  • D On a Splunk server running Splunk DB Connect.
Explanation

An Enterprise Security search head needs top-level visibility across the Splunk deployment so it can run searches and correlation activity over the relevant security data. Splunk documents Enterprise Security deployment on a dedicated search head or dedicated search head cluster.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!