I am running an old version of the add-on and have just recently gotten it working. What advantage would I get from upgrading to the new add-on? Does it collect more data or data from more sources? I think I will work towards upgrading if that will improve the ability to fit the Sep logs to the CIM.
Yes, you should definitely upgrade.
If you are currently using version 2.0.0, see the release notes for the important issue that we fixed that affects that release:
http://docs.splunk.com/Documentation/AddOns/latest/SymantecEP/Releasenotes
If you are currently using TA-sep and TA-sav, packaged in Enterprise Security, read the documentation for full description of how the newly supported add-on now maps to the CIM: http://docs.splunk.com/Documentation/AddOns/latest/SymantecEP/Sourcetypes