SPLK-3001 · Question #42
Where should an ES search head be installed?
The correct answer is C. On a server with a new install of Splunk. Installing Splunk Enterprise Security (ES) on a fresh Splunk instance (option C) is required because ES is a complex premium app with strict dependencies and resource demands - a clean install ensures no pre-existing apps, configurations, or data conflicts interfere with ES's…
Question
Where should an ES search head be installed?
Options
- AOn a Splunk server with top level visibility.
- BOn any Splunk server.
- COn a server with a new install of Splunk.
- DOn a Splunk server running Splunk DB Connect.
How the community answered
(57 responses)- A4% (2)
- B2% (1)
- C93% (53)
- D2% (1)
Explanation
Installing Splunk Enterprise Security (ES) on a fresh Splunk instance (option C) is required because ES is a complex premium app with strict dependencies and resource demands - a clean install ensures no pre-existing apps, configurations, or data conflicts interfere with ES's data models, saved searches, and correlation rules.
Why the distractors are wrong:
- A - "Top level visibility" is not a defined Splunk architecture requirement; ES placement is about isolation, not network visibility hierarchy.
- B - Installing on any Splunk server risks conflicts with existing apps and configurations; ES needs a dedicated environment.
- D - Running ES alongside Splunk DB Connect on the same instance is unsupported and can cause resource contention and app conflicts; ES needs a clean slate.
Memory tip: Think "ES = Exclusive Setup." Enterprise Security is too demanding to share a home - it always moves into a fresh house of its own.
Topics
Community Discussion
No community discussion yet for this question.