When deploying ITSI on a distributed Splunk installation, which component must be installed on the search head(s)?
When deploying ITSI on a distributed Splunk installation, which component must be installed on the search head(s)?
When deploying ITSI (IT Service Intelligence) on a distributed Splunk installation, all ITSI components must be installed on the search head(s). This ensures that the full functionality of ITSI, including ITSI dashboards, KPIs, and other features, can be accessed and utilized from the search head, which is responsible for managing searches and reporting in a Splunk environment.
C - slide 117.
c is correct
C should be right, since in a distributed or on one-server installation everything should go to the Search Head. In a distributed environment set indexAndForward = false.
Slight conflict between B and C: 1: slide 427 says: ITSI Component Locations • Search heads: all ITSI • Indexers: SA-IndexCreation • ITSI indexes • License Master: SA-ITSI-Licensechecker and SA-UserAccess per slide 429 Scenario: Distributed Search • Extract ITSI app package in etc/apps • Copy SA-IndexCreation to the indexers • Copy SA-ITSI-Licensechecker and SA-UserAccess to the license master • Restart Splunk on all servers
B - as per slide 429 Scenario: Distributed Search • Extract ITSI app package in etc/apps • Copy SA-IndexCreation to the indexers • Copy SA-ITSI-Licensechecker and SA-UserAccess to the license master • Restart Splunk on all servers