All Apps and Add-ons

Splunk for Citrix doesn't work :-(

sbeamro
Explorer

Hi,
I'm using the latest Splunk version , and netscaler 10.1.
I have installed on the index head the Splunk_TA_Citrix-Netscaler & IPFIX, and on search head I have installed the software and the TA & IPFIX.

I can see over the Splunk that data is getting -

12/16/14 11:54:21.000 AM Dec 16
11:54:21 10.40.2.224
16/12/2014:11:47:21 GMT 0-PPE-0 : UI
CMD_EXECUTED 1489 0 : User NDS_support
- Remote_ip 10.56.182.0 - Command "show ns hardware" - Status "Success"
• host = 10.40.2.224 • source =
udp:514 • sourcetype = syslog

when I'm getting to the splunk for Netscaler software it doesn't recognize the Netscaler.

I've modified over Splunk_TA_Citrix-NetScaler/default/inputs.conf to be -

[udp://514]
#connection_host = dns
sourcetype = ns_log
index = netscaler
disabled = false

# A separate IPFIX addon is needed in order for the following stanza to work.  http://apps.splunk.com/app/1801/
[ipfix://NetScaler_AppFlow]
sourcetype = appflow
index = netscaler
address = 0.0.0.0
port = 4739
buffer = 1048576
disabled = true
0 Karma

jconger
Splunk Employee
Splunk Employee

Looks like your ipfix input is disabled.

0 Karma

sbeamro
Explorer

I've tried to change it to false - nothing has changed 😞

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...