The documentation for SplunkforSymantec state:
After downloading the app and going through the set up process, you still need to install either the Symantec 11 Technology Add-on or Symantec 12 Technology Add-on. If you are currently running both products, you should install both TAs. They are included with this app in the appserver/addons directory.
How do you install the TA?
Also in the /opt/splunk/etc/apps/SplunkforSymantec/appserver/addons/TA-sepapp12/README there are references to:
- Copy the following file: $SPLUNK_HOME/etc/apps/TA-sep/default/inputs.conf.local To the following location: $SPLUNK_HOME/etc/apps/TA-sep/local/inputs.conf
These locations do not exist!