nerdexam
Splunk

SPLK-3001 · Question #16

A site has a single existing search head which hosts a mix of both CIM and non-CIM compliant applications. All of the applications are mission-critical. The customer wants to carefully control cost…

The correct answer is B. Add a new search head and install ES on it. Installing Splunk Enterprise Security (ES) on a dedicated search head (Option B) is the Splunk-recommended best practice because ES is resource-intensive and performs best in isolation - sharing a search head with other apps causes resource contention that degrades ES…

ES Deployment

Question

A site has a single existing search head which hosts a mix of both CIM and non-CIM compliant applications. All of the applications are mission-critical. The customer wants to carefully control cost, but wants good ES performance. What is the best practice for installing ES?

Options

  • AInstall ES on the existing search head.
  • BAdd a new search head and install ES on it.
  • CIncrease the number of CPUs and amount of memory on the search head, then install ES.
  • DDelete the non-CIM-compliant apps from the search head, then install ES.

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    83% (24)
  • C
    3% (1)
  • D
    10% (3)

Explanation

Installing Splunk Enterprise Security (ES) on a dedicated search head (Option B) is the Splunk-recommended best practice because ES is resource-intensive and performs best in isolation - sharing a search head with other apps causes resource contention that degrades ES performance and risks the other apps as well.

Why the distractors fail:

  • A violates the dedicated search head recommendation; mixing ES with other apps on the same instance leads to poor ES performance and risks destabilizing the existing mission-critical apps.
  • C adds hardware resources but does not solve the isolation problem - ES and other apps would still compete for those resources, and the cost of over-provisioning a single large box often exceeds the cost of a second, right-sized search head.
  • D is eliminated by the constraint that all apps are mission-critical; deleting the non-CIM apps is not an option, even though ES does require CIM compliance from its data sources.

Memory tip: Think of ES as a "VIP tenant" - it demands its own search head and won't share nicely. Whenever an exam scenario involves ES + cost control + existing apps, the answer almost always points to a new dedicated search head, because mixing ES is the one thing Splunk explicitly warns against in its capacity planning docs.

Topics

#ES deployment#search head isolation#best practices#CIM compliance

Community Discussion

No community discussion yet for this question.

Full SPLK-3001 Practice