SPLK-3002 Exam QuestionsBrowse all questions from this exam

SPLK-3002 Exam - Question 13


When deploying ITSI on a distributed Splunk installation, which component must be installed on the search head(s)?

Show Answer
Correct Answer: CD

When deploying ITSI (IT Service Intelligence) on a distributed Splunk installation, all ITSI components must be installed on the search head(s). This ensures that the full functionality of ITSI, including ITSI dashboards, KPIs, and other features, can be accessed and utilized from the search head, which is responsible for managing searches and reporting in a Splunk environment.

Discussion

5 comments
Sign in to comment
otb_282Option: C
Mar 14, 2023

C - slide 117.

Manish7Option: C
Oct 30, 2023

c is correct

anwar_mianOption: C
Oct 21, 2023

C should be right, since in a distributed or on one-server installation everything should go to the Search Head. In a distributed environment set indexAndForward = false.

Ash111Option: B
Mar 7, 2024

B - as per slide 429 Scenario: Distributed Search • Extract ITSI app package in etc/apps • Copy SA-IndexCreation to the indexers • Copy SA-ITSI-Licensechecker and SA-UserAccess to the license master • Restart Splunk on all servers

Ash111Option: B
Mar 7, 2024

Slight conflict between B and C: 1: slide 427 says: ITSI Component Locations • Search heads: all ITSI • Indexers: SA-IndexCreation • ITSI indexes • License Master: SA-ITSI-Licensechecker and SA-UserAccess per slide 429 Scenario: Distributed Search • Extract ITSI app package in etc/apps • Copy SA-IndexCreation to the indexers • Copy SA-ITSI-Licensechecker and SA-UserAccess to the license master • Restart Splunk on all servers