All Apps and Add-ons

Splunk for Citrix doesn't work :-(

sbeamro
Explorer

Hi,
I'm using the latest Splunk version , and netscaler 10.1.
I have installed on the index head the Splunk_TA_Citrix-Netscaler & IPFIX, and on search head I have installed the software and the TA & IPFIX.

I can see over the Splunk that data is getting -

12/16/14 11:54:21.000 AM Dec 16
11:54:21 10.40.2.224
16/12/2014:11:47:21 GMT 0-PPE-0 : UI
CMD_EXECUTED 1489 0 : User NDS_support
- Remote_ip 10.56.182.0 - Command "show ns hardware" - Status "Success"
• host = 10.40.2.224 • source =
udp:514 • sourcetype = syslog

when I'm getting to the splunk for Netscaler software it doesn't recognize the Netscaler.

I've modified over Splunk_TA_Citrix-NetScaler/default/inputs.conf to be -

[udp://514]
#connection_host = dns
sourcetype = ns_log
index = netscaler
disabled = false

# A separate IPFIX addon is needed in order for the following stanza to work.  http://apps.splunk.com/app/1801/
[ipfix://NetScaler_AppFlow]
sourcetype = appflow
index = netscaler
address = 0.0.0.0
port = 4739
buffer = 1048576
disabled = true
0 Karma

jconger
Splunk Employee
Splunk Employee

Looks like your ipfix input is disabled.

0 Karma

sbeamro
Explorer

I've tried to change it to false - nothing has changed 😞

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...