All Apps and Add-ons

Netscaler - Pulling syslog Data - UI Still Wants Setup

nychawk
Communicator

I have several Netscalers sending their data to syslog. My syslog server has UF installed, and my inputs.conf is setup in the following manner:

[monitor:///syslog-data/all-my-netscalers-in-one.log]
source=syslog
sourcetype=citrix:netscaler:syslog
host =

When I go to my search head, and select the Netscaler app, I get queried for the apps setup, which is asking for netscaler devices, user and passwords; I am not expecting this.

I've verified that my data is getting indexed.

I am missing something, I've scrubbed the apps doc, and not sure what else is needed.

Thanks all in advance,

-mi

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

Hi, the app is currently separate from the add-on; while that might change in the future, you're probably better off taking it the other direction. I would try following the Add-on's documentation to get the data in, then let's see if the App works with that data. Since the App has its own inputs, you might want to disable those and start from the Add-on's documentation. Since the Add-on is supported, you can open a ticket if following the documentation doesn't produce the expected data, we'd be happy to look into it further.

0 Karma

darlas
Communicator

Can you specify what the name of the App is? The documentation for this Add-on says "After the Splunk platform indexes the events, you can consume the data using the prebuilt panels included with the add-on", which makes it sounds like the visualization is contained in this Add-on. Appreciate any clarification on this.

Thanks.

0 Karma

Skins
Path Finder

there are 4 pre-built panels included in the TA which you can add to dashboards.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...