Hello,
I have Splunk 6 and Enterprise Security 3 (latest version). I'm also indexing data from our Symantec endpoints.
There is an app: "Splunk for Symantec" but also technology add-ons: "TA-sep" and "TA-sav" (depending on Symantec version).
Considering that I'm running Enterprise Security, which apps and add-ons do I really need?
This is my understanding:
I'm a little confused between the Symantec App and the Symantec TA's and how they are different and how they affect (or don't affect) Enterprise Security so I'm just looking for some clarity. For example, if I disable the Splunk for Symantec app does that mean I will stop indexing Symantec data? And if so, then what are the TA's for? Ditto for BlueCoat... there is an app but also a technology add-on.
Thanks!
Hi,
ES uses data from the CIM, so you need the TA's to map the data. The Symantec app can provide Symantec specific reports in addition.
Jack
Hi,
ES uses data from the CIM, so you need the TA's to map the data. The Symantec app can provide Symantec specific reports in addition.
Jack
Thanks, that's what I thought... I'll disable the Symantec App and then run a test to see if it affected the indexing/data in any way.
Where do I download Symantec 12 Technology Add-on?????
The TA is included with the app - try here: $SPLUNK_HOME/etc/apps/SplunkforSymantec/appserver/addons/TA-sepapp12