Can I combine enterprise security 3.3.0 with PCI 2.1.1 AND all of my other non CIM compliant apps into one big search head cluster?
According to the docs, I can run PCI and ES on the same search head. I have 8 search heads available and am only running ES on one of them. To facilitate redundancy and easy administration, could I combine ES with PCI and all my other "non security" related apps and manage manage all 8 search heads as one big cluster. All search heads would be managed using the deployer and look pretty much identical to eachother.
If I cannot do this, why?
Thanks so much!
Fortunately, the status quo has changed in the last couple years! The PCI app is now designed to co-habitate with Splunk Enterprise Security on the same SH or SHC. As a bonus, that means ES and PCI will use the same data model accelerations when configured together. Check the PCI app Release Notes page for the compatibility with various ES versions.
It's not a clear cut Yes and No. There are some customers out there that are forced, by lack of hardware etc, to co-habitate PCI and ES on the same search head(s). And depending on data volumes and usage patterns, it does work, but it is high touch.
This is not recommended though, but it is possible, as long as you're aware of how CIM and SI comes into play between PCI and ES.
Avoid it if possible.
Unfortunately, the PCI and ES apps cannot cohab on the same search head at this time. Also, the PCI app doesn't support search head clustering. You can install ES on one SH or SH cluster while running PCI on another independent, non-clustered SH. Both ES and PCI SH's can reference the same indexers, but only if those indexers have plentiful CPU cores and I/O capacity beyond the recommended hardware specifications.