All Apps and Add-ons

Splunk for Citrix NetScaler with Appflow: Why can't I see anything in "NetScaler Overview", but I can in "AppFlow Overview"?

Silviav
New Member

Hi,

I'm trying to use Slunk for NetScaler, but I can't understand why I can't see anything in "NetScaler Overview", but there are a lot of events in "Search NetScaler data" and I can also see a lot of data in "AppFlow Overview".

Is it "normal"? I'm still learning how to use it.
I'm using the NetScaler only with a XenMobile appliance.

0 Karma

jconger
Splunk Employee
Splunk Employee

Do you have syslog configured to send data to Splunk from the NetScaler?

Also, what do you get when you run the following search:

eventtype=netscaler* | stats count by eventtype index
0 Karma

Silviav
New Member

Thank you very much for your answer!

I think so.
When I run that search I get;

EVENTYPE INDEX COUNT
netscaler netscaler 123380
netscaler_appflow netscaler 123380

I though that the problem was there isn't a field log_type in the events (the search of "Netscaler Overview" is

eventtype=netscaler | timechart count by log_type usenull=f

)

Do you think it could be possible?

0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...