All Apps and Add-ons

Splunk for Citrix NetScaler with Appflow: Why can't I see anything in "NetScaler Overview", but I can in "AppFlow Overview"?

Silviav
New Member

Hi,

I'm trying to use Slunk for NetScaler, but I can't understand why I can't see anything in "NetScaler Overview", but there are a lot of events in "Search NetScaler data" and I can also see a lot of data in "AppFlow Overview".

Is it "normal"? I'm still learning how to use it.
I'm using the NetScaler only with a XenMobile appliance.

0 Karma

jconger
Splunk Employee
Splunk Employee

Do you have syslog configured to send data to Splunk from the NetScaler?

Also, what do you get when you run the following search:

eventtype=netscaler* | stats count by eventtype index
0 Karma

Silviav
New Member

Thank you very much for your answer!

I think so.
When I run that search I get;

EVENTYPE INDEX COUNT
netscaler netscaler 123380
netscaler_appflow netscaler 123380

I though that the problem was there isn't a field log_type in the events (the search of "Netscaler Overview" is

eventtype=netscaler | timechart count by log_type usenull=f

)

Do you think it could be possible?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...