Splunk Enterprise Security

Are there issues with adding Enterprise Security 3.3.0 with my overall search head cluster?

JoeBlake
Engager

Can I combine enterprise security 3.3.0 with PCI 2.1.1 AND all of my other non CIM compliant apps into one big search head cluster?

According to the docs, I can run PCI and ES on the same search head. I have 8 search heads available and am only running ES on one of them. To facilitate redundancy and easy administration, could I combine ES with PCI and all my other "non security" related apps and manage manage all 8 search heads as one big cluster. All search heads would be managed using the deployer and look pretty much identical to eachother.

If I cannot do this, why?

Thanks so much!

ekost
Splunk Employee
Splunk Employee

Fortunately, the status quo has changed in the last couple years! The PCI app is now designed to co-habitate with Splunk Enterprise Security on the same SH or SHC. As a bonus, that means ES and PCI will use the same data model accelerations when configured together. Check the PCI app Release Notes page for the compatibility with various ES versions.

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

It's not a clear cut Yes and No. There are some customers out there that are forced, by lack of hardware etc, to co-habitate PCI and ES on the same search head(s). And depending on data volumes and usage patterns, it does work, but it is high touch.

This is not recommended though, but it is possible, as long as you're aware of how CIM and SI comes into play between PCI and ES.

Avoid it if possible.

0 Karma

ekost
Splunk Employee
Splunk Employee

Unfortunately, the PCI and ES apps cannot cohab on the same search head at this time. Also, the PCI app doesn't support search head clustering. You can install ES on one SH or SH cluster while running PCI on another independent, non-clustered SH. Both ES and PCI SH's can reference the same indexers, but only if those indexers have plentiful CPU cores and I/O capacity beyond the recommended hardware specifications.

stefan1988
Path Finder

Would this mean you can also use the same CIM accelerated data models on different SHC?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...