Splunk Enterprise Security

Are there any disadvantages of installing Windows Infra app on the ES search head ?

damode
Motivator

Are there any disadvantages of installing Windows Infra app on the ES search head if the SH has 32Gb ram and 24 CPU ?

0 Karma

The_Simko
Path Finder

Howdy. The main reason to avoid non-security apps on an Enterprise Security Search Head is contention. That server has only 24 cores. By default half of your search slots (cores +6) are allowed for scheduled searches. So that's 15 concurrent scheduled searches. ES uses these slots.  Better is to move to 75% of search slots  allowed for scheduled searches, but even with that it's likely that scheduled searches and data model acceleration will need all of those cores. Putting other apps on the box will fight for those limited resources.
The second reason is that some apps will contend for configs. It's been a while since I saw that, but an app with its own tags may battle ES and CIM's settings. 
Ergo, it's way better to keep your ES Search Head separate from your general purpose search heads. 
-- Michael S 

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...