All Apps and Add-ons

How to get data into the Citrix XenApp app?

Jason
Motivator

In the new Splunk for Citrix XenApp app, I see index definitions, but no documentation on how to get data in, what data is expected as what sourcetypes, etc. I need to instruct the forwarders on what data to collect, what to sourcetype it as, and what index to put it in. Did I miss a readme in there somewhere?

0 Karma
1 Solution

bsonposh
Communicator

There are "TA" (Technology Add-ons) included with the application. These are located at \appserver\addons.

  • TA-XA**-Broker goes on the ZDC
  • TA-XA**-Server goes on each XenApp Server
  • TA-CitrixLicensing-1 goes on the Citrix Licensing server

You can use deployment server to handle deployment or you can do it manually.

There are docs forthcoming.

View solution in original post

kelvinlow
New Member

Hi, I cant see any data populated to Splunk server even though Indexes are created. Just to curios, am i suppose to create datasources?

0 Karma

kelvinlow
New Member

Thanks for sharing. I've done all the Splunk App & TA-XA5 installed on Citrix server Xenapp5 but no data being sent to splunk server. Can anyone advise? many thanks.

attached some of error capture from splunkd.
09-07-2012 14:33:53.437 +0800 ERROR WinEventLogInputProcessor - processLogChannel: Failed to checkpoint for channel='Setup'
09-07-2012 14:33:53.437 +0800 INFO WinEventLogInputProcessor - main-thread: It seems like the Windows Event Log channel 'Setup' has been reset
09-07-2012 14:34:43.828 +0800 ERROR ExecProcessor - message from "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -command " &'C:\Program Files\SplunkUniversalForwarder\etc\apps\TA-XA5-Broker\bin\powershell\GetXAServerLoad5.ps1'" -index xenapp" The term 'C:\Program Files\SplunkUniversalForwarder\etc\apps\TA-XA5-Broker\bin\
09-07-2012 14:34:43.828 +0800 ERROR ExecProcessor - message from "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -command " &'C:\Program Files\SplunkUniversalForwarder\etc\apps\TA-XA5-Broker\bin\powershell\GetXAServerLoad5.ps1'" -index xenapp" powershell\GetXAServerLoad5.ps1' is not recognized as a cmdlet, function, opera
09-07-2012 14:34:43.828 +0800 ERROR ExecProcessor - message from "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -command " &'C:\Program Files\SplunkUniversalForwarder\etc\apps\TA-XA5-Broker\bin\powershell\GetXAServerLoad5.ps1'" -index xenapp" ble program, or script file. Verify the term and try again.

0 Karma

bwindham
Path Finder

bsonposh,
Thanks for the quick reply and pardon my ignorance, but where do the TA's need to be deployed exactly on the XA server?
Under etc/apps? And as for the TA-60-Server, do I copy the whole directory from $splunkhome/splunk/etc/apps/SpunkForXenApps/appserver/addon to the location (???) on XA?
Does anything else need to be configured on XenApp Server application to send data?
Thanks in advance.....I really want to get this going!

0 Karma

Jason
Motivator

Yes, the TA-* apps will go into etc/apps to become part of Splunk's active configuration. Try to ask questions as new questions on the site, not in answers to an existing question.

0 Karma

bwindham
Path Finder

I'm looking to do this also but unsure of the steps. Does a universal forwarder need to reside on each XenApp server? How should it be configured and where should the TA files reside on the XenApp server too?

0 Karma

bsonposh
Communicator

Yes... the UF needs to be on all XenApp servers and the TA's deployed.

TA-XA*-Broker goes on one or two XenApp servers... preferably not one that supports users.
TA-XA*-Server goes on ALL XenApp servers.

0 Karma

bsonposh
Communicator

There are "TA" (Technology Add-ons) included with the application. These are located at \appserver\addons.

  • TA-XA**-Broker goes on the ZDC
  • TA-XA**-Server goes on each XenApp Server
  • TA-CitrixLicensing-1 goes on the Citrix Licensing server

You can use deployment server to handle deployment or you can do it manually.

There are docs forthcoming.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...