SPLK-3001 · Question #16
A site has a single existing search head which hosts a mix of both CIM and non-CIM compliant applications. All of the applications are mission-critical. The customer wants to carefully control cost…
The correct answer is B. Add a new search head and install ES on it. Installing Splunk Enterprise Security (ES) on a dedicated search head (Option B) is the Splunk-recommended best practice because ES is resource-intensive and performs best in isolation - sharing a search head with other apps causes resource contention that degrades ES…
Question
A site has a single existing search head which hosts a mix of both CIM and non-CIM compliant applications. All of the applications are mission-critical. The customer wants to carefully control cost, but wants good ES performance. What is the best practice for installing ES?
Options
- AInstall ES on the existing search head.
- BAdd a new search head and install ES on it.
- CIncrease the number of CPUs and amount of memory on the search head, then install ES.
- DDelete the non-CIM-compliant apps from the search head, then install ES.
How the community answered
(29 responses)- A3% (1)
- B83% (24)
- C3% (1)
- D10% (3)
Explanation
Installing Splunk Enterprise Security (ES) on a dedicated search head (Option B) is the Splunk-recommended best practice because ES is resource-intensive and performs best in isolation - sharing a search head with other apps causes resource contention that degrades ES performance and risks the other apps as well.
Why the distractors fail:
- A violates the dedicated search head recommendation; mixing ES with other apps on the same instance leads to poor ES performance and risks destabilizing the existing mission-critical apps.
- C adds hardware resources but does not solve the isolation problem - ES and other apps would still compete for those resources, and the cost of over-provisioning a single large box often exceeds the cost of a second, right-sized search head.
- D is eliminated by the constraint that all apps are mission-critical; deleting the non-CIM apps is not an option, even though ES does require CIM compliance from its data sources.
Memory tip: Think of ES as a "VIP tenant" - it demands its own search head and won't share nicely. Whenever an exam scenario involves ES + cost control + existing apps, the answer almost always points to a new dedicated search head, because mixing ES is the one thing Splunk explicitly warns against in its capacity planning docs.
Topics
Community Discussion
No community discussion yet for this question.