SPLK-3001 Exam QuestionsBrowse all questions from this exam

SPLK-3001 Exam - Question 44


ES needs to be installed on a search head with which of the following options?

Show Answer
Correct Answer: AD

Enterprise Security (ES) needs to be installed on a search head with only default built-in and CIM-compliant apps because ES relies heavily on the Common Information Model (CIM) and Splunk's built-in functionalities to operate efficiently. Other non-CIM-compliant apps might interfere with ES's operations or cause performance issues.

Discussion

7 comments
Sign in to comment
okseyOption: D
Nov 20, 2020

D is the ans

SriAkulaOption: D
Dec 4, 2021

Answer: D ( Clearly specified in Splunk ES documentation that Splunk Uses by default CIM also default apps should not be deleted)

brettwOption: A
Feb 24, 2022

ES recommended installation is on a dedicated search head with only the default installation, due to the number of resources required for ES to run efficiently.

guiraxOption: D
Dec 1, 2021

D is correct ES generally requires a new, dedicated search head or search head cluster – ES is only compatible with other CIM-compatible apps – ES adds a large number of searches and search results Administering Splunk Enterprise Security page 113

qtygbapjpesdayazkoOption: D
Apr 13, 2023

D. Only default built-in and CIM-compliant apps.

andy73Option: D
Dec 1, 2021

D is correct

adamscaOption: D
Jun 8, 2024

D is Correct