ES needs to be installed on a search head with which of the following options?
ES needs to be installed on a search head with which of the following options?
Enterprise Security (ES) needs to be installed on a search head with only default built-in and CIM-compliant apps because ES relies heavily on the Common Information Model (CIM) and Splunk's built-in functionalities to operate efficiently. Other non-CIM-compliant apps might interfere with ES's operations or cause performance issues.
D is the ans
ES recommended installation is on a dedicated search head with only the default installation, due to the number of resources required for ES to run efficiently.
Answer: D ( Clearly specified in Splunk ES documentation that Splunk Uses by default CIM also default apps should not be deleted)
D. Only default built-in and CIM-compliant apps.
D is correct ES generally requires a new, dedicated search head or search head cluster – ES is only compatible with other CIM-compatible apps – ES adds a large number of searches and search results Administering Splunk Enterprise Security page 113
D is Correct
D is correct