nerdexam
Splunk

SPLK-3001 · Question #42

Where should an ES search head be installed?

The correct answer is C. On a server with a new install of Splunk. Installing Splunk Enterprise Security (ES) on a fresh Splunk instance (option C) is required because ES is a complex premium app with strict dependencies and resource demands - a clean install ensures no pre-existing apps, configurations, or data conflicts interfere with ES's…

Installation and Configuration

Question

Where should an ES search head be installed?

Options

  • AOn a Splunk server with top level visibility.
  • BOn any Splunk server.
  • COn a server with a new install of Splunk.
  • DOn a Splunk server running Splunk DB Connect.

How the community answered

(57 responses)
  • A
    4% (2)
  • B
    2% (1)
  • C
    93% (53)
  • D
    2% (1)

Explanation

Installing Splunk Enterprise Security (ES) on a fresh Splunk instance (option C) is required because ES is a complex premium app with strict dependencies and resource demands - a clean install ensures no pre-existing apps, configurations, or data conflicts interfere with ES's data models, saved searches, and correlation rules.

Why the distractors are wrong:

  • A - "Top level visibility" is not a defined Splunk architecture requirement; ES placement is about isolation, not network visibility hierarchy.
  • B - Installing on any Splunk server risks conflicts with existing apps and configurations; ES needs a dedicated environment.
  • D - Running ES alongside Splunk DB Connect on the same instance is unsupported and can cause resource contention and app conflicts; ES needs a clean slate.

Memory tip: Think "ES = Exclusive Setup." Enterprise Security is too demanding to share a home - it always moves into a fresh house of its own.

Topics

#ES installation#search head#Splunk server

Community Discussion

No community discussion yet for this question.

Full SPLK-3001 Practice