ExamGecko
Question list
Search
Search

Question 64 - SPLK-3002 discussion

Report
Export

Which of the following is a recommended best practice for ITSI installation?

A.
ITSI should not be installed on search heads that have Enterprise Security installed.
Answers
A.
ITSI should not be installed on search heads that have Enterprise Security installed.
B.
Before installing ITSI, make sure the Common Information Model (CIM) is installed.
Answers
B.
Before installing ITSI, make sure the Common Information Model (CIM) is installed.
C.
Install the Machine Learning Toolkit app if anomaly detection must be configured.
Answers
C.
Install the Machine Learning Toolkit app if anomaly detection must be configured.
D.
Install ITSI on one search head in a search head cluster and migrate the configuration bundle to other search heads.
Answers
D.
Install ITSI on one search head in a search head cluster and migrate the configuration bundle to other search heads.
Suggested answer: A

Explanation:

One of the recommended best practices for Splunk IT Service Intelligence (ITSI) installation is to avoid installing ITSI on search heads that already have Splunk Enterprise Security (ES) installed. This recommendation stems from potential resource conflicts and performance issues that can arise when both resource-intensive applications are deployed on the same instance. Both ITSI and ES are complex applications that require significant system resources to function effectively, and running them concurrently on the same search head can lead to degraded performance, conflicts in resource allocation, and potential stability issues. It's generally advised to segregate these applications onto separate Splunk instances to ensure optimal performance and stability for both platforms.

asked 23/09/2024
Ruben Dallibor
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first