Splunk Enterprise Security

Splunk for Symantec vs TA-sep/sav - what's the difference?

echojacques
Builder

Hello,

I have Splunk 6 and Enterprise Security 3 (latest version). I'm also indexing data from our Symantec endpoints.

There is an app: "Splunk for Symantec" but also technology add-ons: "TA-sep" and "TA-sav" (depending on Symantec version).

Considering that I'm running Enterprise Security, which apps and add-ons do I really need?

This is my understanding:

  • I'm assuming that I don't need the full "Splunk for Symantec" app since I have Enterprise Security and ES has the endpoint/malware dashboards that I need.
  • I'm assuming that I need the TA-sep and TA-sav apps to index the Symantec data properly.

I'm a little confused between the Symantec App and the Symantec TA's and how they are different and how they affect (or don't affect) Enterprise Security so I'm just looking for some clarity. For example, if I disable the Splunk for Symantec app does that mean I will stop indexing Symantec data? And if so, then what are the TA's for? Ditto for BlueCoat... there is an app but also a technology add-on.

Thanks!

1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

Hi,

ES uses data from the CIM, so you need the TA's to map the data. The Symantec app can provide Symantec specific reports in addition.

Jack

View solution in original post

jcoates_splunk
Splunk Employee
Splunk Employee

Hi,

ES uses data from the CIM, so you need the TA's to map the data. The Symantec app can provide Symantec specific reports in addition.

Jack

echojacques
Builder

Thanks, that's what I thought... I'll disable the Symantec App and then run a test to see if it affected the indexing/data in any way.

0 Karma

demonio316
New Member

Where do I download Symantec 12 Technology Add-on?????

0 Karma

bnorthway
Path Finder

The TA is included with the app - try here: $SPLUNK_HOME/etc/apps/SplunkforSymantec/appserver/addons/TA-sepapp12

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...