SPLK-3002 · Question #70
SPLK-3002 Question #70: Real Exam Question with Answer & Explanation
The correct answer is A. ITSI should not be installed on search heads that have Enterprise Security installed.. One of the recommended best practices for Splunk IT Service Intelligence (ITSI) installation is to avoid installing ITSI on search heads that already have Splunk Enterprise Security (ES) installed. This recommendation stems from potential resource conflicts and performance issues
Question
Options
- AITSI should not be installed on search heads that have Enterprise Security installed.
- BBefore installing ITSI, make sure the Common Information Model (CIM) is installed.
- CInstall the Machine Learning Toolkit app if anomaly detection must be configured.
- DInstall ITSI on one search head in a search head cluster and migrate the configuration bundle to
Explanation
One of the recommended best practices for Splunk IT Service Intelligence (ITSI) installation is to avoid installing ITSI on search heads that already have Splunk Enterprise Security (ES) installed. This recommendation stems from potential resource conflicts and performance issues that can arise when both resource-intensive applications are deployed on the same instance. Both ITSI and ES are complex applications that require significant system resources to function effectively, and running them concurrently on the same search head can lead to degraded performance, conflicts in resource allocation, and potential stability issues. It's generally advised to segregate these applications onto separate Splunk instances to ensure optimal performance and stability for
Community Discussion
No community discussion yet for this question.