Installation

How do you install TA's for SplunkforSymantec?

HackerAce1
Engager

The documentation for SplunkforSymantec state:

After downloading the app and going through the set up process, you still need to install either the Symantec 11 Technology Add-on or Symantec 12 Technology Add-on. If you are currently running both products, you should install both TAs. They are included with this app in the appserver/addons directory.

How do you install the TA?

Also in the /opt/splunk/etc/apps/SplunkforSymantec/appserver/addons/TA-sepapp12/README there are references to:

  1. Copy the following file: $SPLUNK_HOME/etc/apps/TA-sep/default/inputs.conf.local To the following location: $SPLUNK_HOME/etc/apps/TA-sep/local/inputs.conf

These locations do not exist!

Labels (1)
0 Karma

sphadnis
Path Finder

I have the similar issue - can anyone elaborate on the installation instructions? I have a couple of forwarders, and a couple of indexers and a search head (all on different machines). As I understood, I am required to install the TA on the indexers - how does one achieve that? I dont see any option for spl or tgz file.

0 Karma

mattspierce
Explorer

I'm having a similar issue. I am seeing events form the symantec server in the data. I do not see the Symantec Plugin recognizing that data. I've located the TA for sep11 and sep12 in /opt/splunk/etc/apps/SplunkforSymantec/appserver/addons but there are no tgz or spl file to install.

0 Karma

jordanperks
Path Finder

Are you putting those on your SEP server? I believe that is only required if you are installing a UF on your SEP server.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...