Hi,
I'm trying to use Slunk for NetScaler, but I can't understand why I can't see anything in "NetScaler Overview", but there are a lot of events in "Search NetScaler data" and I can also see a lot of data in "AppFlow Overview".
Is it "normal"? I'm still learning how to use it.
I'm using the NetScaler only with a XenMobile appliance.
Do you have syslog configured to send data to Splunk from the NetScaler?
Also, what do you get when you run the following search:
eventtype=netscaler* | stats count by eventtype index
Thank you very much for your answer!
I think so.
When I run that search I get;
EVENTYPE INDEX COUNT
netscaler netscaler 123380
netscaler_appflow netscaler 123380
I though that the problem was there isn't a field log_type in the events (the search of "Netscaler Overview" is
eventtype=netscaler | timechart count by log_type usenull=f
)
Do you think it could be possible?