I have latest version of splunk 6.0.3 an i installed symantec.now i dont know how to give the input for that app please tell me how to give the input and how to make that work.
Hi,
I hope you figure it out.
But in case you can follow my previous post:
feedback-from-installation-of-symantec-app
This is the inputs.conf file that you have to configure in the TA.
The TA has to be sent on the forwarder on your SEP server AND on the Indexer.
The Application has to be installed on the Search Head. This is what is written in the documentation.