Splunk Enterprise Security

Are there issues with adding Enterprise Security 3.3.0 with my overall search head cluster?

JoeBlake
Engager

Can I combine enterprise security 3.3.0 with PCI 2.1.1 AND all of my other non CIM compliant apps into one big search head cluster?

According to the docs, I can run PCI and ES on the same search head. I have 8 search heads available and am only running ES on one of them. To facilitate redundancy and easy administration, could I combine ES with PCI and all my other "non security" related apps and manage manage all 8 search heads as one big cluster. All search heads would be managed using the deployer and look pretty much identical to eachother.

If I cannot do this, why?

Thanks so much!

ekost
Splunk Employee
Splunk Employee

Fortunately, the status quo has changed in the last couple years! The PCI app is now designed to co-habitate with Splunk Enterprise Security on the same SH or SHC. As a bonus, that means ES and PCI will use the same data model accelerations when configured together. Check the PCI app Release Notes page for the compatibility with various ES versions.

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

It's not a clear cut Yes and No. There are some customers out there that are forced, by lack of hardware etc, to co-habitate PCI and ES on the same search head(s). And depending on data volumes and usage patterns, it does work, but it is high touch.

This is not recommended though, but it is possible, as long as you're aware of how CIM and SI comes into play between PCI and ES.

Avoid it if possible.

0 Karma

ekost
Splunk Employee
Splunk Employee

Unfortunately, the PCI and ES apps cannot cohab on the same search head at this time. Also, the PCI app doesn't support search head clustering. You can install ES on one SH or SH cluster while running PCI on another independent, non-clustered SH. Both ES and PCI SH's can reference the same indexers, but only if those indexers have plentiful CPU cores and I/O capacity beyond the recommended hardware specifications.

stefan1988
Path Finder

Would this mean you can also use the same CIM accelerated data models on different SHC?

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Index This | What’s a riddle wrapped in an enigma?

September 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

BORE at .conf25

Boss Of Regular Expression (BORE) was an interactive session run again this year at .conf25 by the brilliant ...

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...