All Apps and Add-ons

We want to install Splunk for Symantec on a Windows server, but what is TA-sepapp12 and how do I install and configure it?

abovebeyond
Communicator

Hey,

We want to install Splunk for Symantec on a Windows server.

I saw the installation guide:
splunkbase.splunk.com/app/1365/#/documentation

I don't understand what the TA-sepapp12 is, where I can find it, and how do I configure it?

Thanks

Tags (1)

ppablo
Retired

Hi @abovebeyond

The app itself has the UI for you to search and visualize your data, but the TA (Add-on) helps with parsing of data for the app such as proper field recognition and extraction. Without the TA, you might be getting strangely formatted data or no data at all in your dashboards.

The bottom of the app's documentation page that you included has the instructions for finding the TA under "Installation".

"They are included with this app in the appserver/addons directory. For single server Splunk instances, the TAs will be on the same server as the app. For distributed Splunk instances, the TAs just needs to go on the indexers and the app just goes on the search heads."

Just below that are instructions for configuring the TA.

Keep in mind that the app is only supported for Splunk 6.0, 5.0, and 4.3 in case you're using 6.1.x or 6.2.x. If you're still having issues, hopefully someone else who has successfully installed/configured the app can chime in or the developer himself.

bnorthway
Path Finder

Are there plans to support Splunk 6.2?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...