nerdexam
Splunk

SPLK-2002(205Q) · Question #115

A Splunk deployment is being architected and the customer will be using Splunk Enterprise Security (ES) and Splunk IT Service Intelligence (ITSI). Through data onboarding and sizing, it is…

The correct answer is B. Two search head clusters, one for ITSI and one for ES. The correct topology to ensure a scalable and performant deployment for the customer's use case is two search head clusters, one for ITSI and one for ES. This configuration provides high availability, load balancing, and isolation for each Splunk app. According to the Splunk…

Splunk Architecture Design

Question

A Splunk deployment is being architected and the customer will be using Splunk Enterprise Security (ES) and Splunk IT Service Intelligence (ITSI). Through data onboarding and sizing, it is determined that over 200 discrete KPIs will be tracked by ITSI and 1TB of data per day by ES. What topology ensures a scalable and performant deployment?

Options

  • ATwo search heads, one for ITSI and one for ES.
  • BTwo search head clusters, one for ITSI and one for ES.
  • COne search head cluster with both ITSI and ES installed.
  • DOne search head with both ITSI and ES installed.

How the community answered

(30 responses)
  • A
    27% (8)
  • B
    50% (15)
  • C
    17% (5)
  • D
    7% (2)

Explanation

The correct topology to ensure a scalable and performant deployment for the customer's use case is two search head clusters, one for ITSI and one for ES. This configuration provides high availability, load balancing, and isolation for each Splunk app. According to the Splunk documentation1, ITSI and ES should not be installed on the same search head or search head cluster, as they have different requirements and may interfere with each other. Having two separate search head clusters allows each app to have its own dedicated resources and configuration, and avoids potential conflicts and performance issues1. The other options are not recommended, as they either have only one search head or search head cluster, which reduces the availability and scalability of the deployment, or they have both ITSI and ES installed on the same search head or search head cluster, which violates the best practices and may cause problems. Therefore, option B is the correct answer, and options A, C, and D are incorrect. 1: Splunk IT Service Intelligence and Splunk Enterprise Security compatibility

Topics

#Enterprise Security#ITSI#search head clustering#architecture design

Community Discussion

No community discussion yet for this question.

Full SPLK-2002(205Q) Practice