All Apps and Add-ons

How to install the add-on for Symantec end point protection?

rlmalci
Explorer

I'm not understanding the installation instructions. I currently have a forwarder installed on the Symantec server and it is forwarding data to the indexer. I've installed the Symantec add-on on the search head but getting error when trying to open the Symantec app. Does the app have to be installed on the indexer? What files do I need to configure and where?

0 Karma

arssi
New Member

I managed to send logs via UniversalForwarder, and I see them on the index.

But the homepage got an error at the first access.

I re-installed the app but still the same.

Anyone have the solution ?

I didn't find any action for this.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@arssi This is an old thread. Please post a new question.

---
If this reply helps you, Karma would be appreciated.
0 Karma

bluecollar
Engager

After much trial and error we cleared out everything and started fresh, we did use the new app for Symantec. and edited our inputs, index conf files. seem to be getting relevant info in Splunk security essentials app as well as independent searches. Its still a work in progress

0 Karma

emmanuel_hivert
New Member

Hi,

do you have return for this problem ?
I would like to receive the SEP log . I don't know if i may install an forwarder and the SEP add on , or i can to configure the SEP manager to send log ( syslog UDP 514 default) to the Splunk Indexer and in this case , has the SEP add on is necessary ?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What error do you get when trying to open the app?

---
If this reply helps you, Karma would be appreciated.
0 Karma

rlmalci
Explorer

I'm getting the 404 Page not found error. It's unable to find the "app/Splunk_TA_symantec-ep/setup" page. I'm not sure if everything is setup correctly. The universal forwarder is installed on the "Symantec" server, the "Symantec end point" app is installed on the "Splunk Search Head". Does the "Symantec end point" app need to be installed on both the forwarder and search head?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...

Index This | How many sevens are there between 1 and 100?

August 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...