Splunk Enterprise Security Certified Admin — Question 45
Where should an ES search head be installed?
Answer options
- A. On a Splunk server with top level visibility.
- B. On any Splunk server.
- C. On a server with a new install of Splunk.
- D. On a Splunk server running Splunk DB Connect.
Correct answer: C
Explanation
The correct answer is C because an ES search head requires a fresh installation of Splunk to function properly. Options A and D suggest specific configurations that may not be suitable for a dedicated search head, while option B is too vague and does not ensure the necessary setup.