Are there any disadvantages of installing Windows Infra app on the ES search head if the SH has 32Gb ram and 24 CPU ?
Howdy. The main reason to avoid non-security apps on an Enterprise Security Search Head is contention. That server has only 24 cores. By default half of your search slots (cores +6) are allowed for scheduled searches. So that's 15 concurrent scheduled searches. ES uses these slots. Better is to move to 75% of search slots allowed for scheduled searches, but even with that it's likely that scheduled searches and data model acceleration will need all of those cores. Putting other apps on the box will fight for those limited resources.
The second reason is that some apps will contend for configs. It's been a while since I saw that, but an app with its own tags may battle ES and CIM's settings.
Ergo, it's way better to keep your ES Search Head separate from your general purpose search heads.
-- Michael S