All Apps and Add-ons

Citrix XenApp Index

aaronkorn
Splunk Employee
Splunk Employee

Are there any indexs that we need to create for the Citrix XenApp Application? We installed the app to the splunk indexer and installed the UF onto the XenApp Servers. Also, does anyone know a link where some good documentation can be found on this app?

0 Karma
1 Solution

bsonposh
Communicator

Verify that you have the TA (Collector) and the splunkforwarder on the XenApp Servers (ta-xa-broker needs to be on one and ta-xa-server needs to be on all the XenApp servers) and make sure that PowerShell execution policy is set to remotesigned.

http://technet.microsoft.com/en-us/library/ee176961.aspx

View solution in original post

0 Karma

aaronkorn
Splunk Employee
Splunk Employee

The only thing that appears to be missing still is the Top 10 IP Clients, Top Client Version, and all ICA Session Info. We checked the .info files and there was another issue with naming where it stated TA-XA65 instead of TA-XA5 but that did not fix the issue.

0 Karma

aaronkorn
Splunk Employee
Splunk Employee

Yes we are still not able to see this data.

0 Karma

bsonposh
Communicator

Is this still a problem?

0 Karma

aaronkorn
Splunk Employee
Splunk Employee

Awesome! The TA-XA-Server\bin *.path was the issue. One I replaced "Broker" with "Server" everything is now showing up. Thanks!

0 Karma

bsonposh
Communicator

Verify that you have the TA (Collector) and the splunkforwarder on the XenApp Servers (ta-xa-broker needs to be on one and ta-xa-server needs to be on all the XenApp servers) and make sure that PowerShell execution policy is set to remotesigned.

http://technet.microsoft.com/en-us/library/ee176961.aspx

0 Karma

bsonposh
Communicator

You can check the inputs.conf and verify that is correct but if you are running on 4.5 I believe there is a bug in the *.path files on the TA.

In TA-XA-Server\bin*.path files make sure the script path is to the Server TA and not the Broker TA.

The License stuff is not a requirement but the licensing dashboard will not populate without it.

0 Karma

aaronkorn
Splunk Employee
Splunk Employee

Also, we have not applied the TA-CitrixLicensing portion. Is this needed? We do not want to deploy that quite yet as we are testing this in dev and the certificate server is also used for production and testing environments.

0 Karma

aaronkorn
Splunk Employee
Splunk Employee

I believe we are on 4.5 and the ta-xa-server is deployed everywhere. I have not tried to run the scripts manually but I can give that a shot. I also noticed that the sourcetypes exist but they are being sent to the main index. I am going to try to configure the inputs.conf file on the citrix boxes. Or would that not help?

Thanks!

0 Karma

bsonposh
Communicator

What version of XenApp? Is the collector (ta-xa-server) deployed everywhere? What happens if you run the PowerShell scripts manually? Any errors in the $Splunk_Home/var/log/splunk/splunkd.log

0 Karma

aaronkorn
Splunk Employee
Splunk Employee

Thanks. It looks like powershell scripts are able to run as we have some data from scripts in splunk. We are missing several sourcetypes which is why many of the dashboard panels are not coming back with any data. We are missing the xenapp, xa_sessions, and Perfmon:LogicalDisk to name a few.

0 Karma

bsonposh
Communicator

The indexes should be create by the app itself. If you have separate indexers and search heads just make sure the dashboard app is on both.

As for the documentation we are doing the official release of this app at Synergy Barcelona and that will include full documentation.

0 Karma

aaronkorn
Splunk Employee
Splunk Employee

Thank you. It appears that all the indexes are created but we are still not gathering any session information.

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...