Hi, I think you should set your source type to citrix:netscaler:syslog rather than ns_log. The CIM mapping and dashboard panels are dependent on this source type. If you have not done so, please download and deploy the latest release of Splunk Add-on for Citrix NetScaler: http://splunkbase.splunk.com/app/2770. Hope it helps. Thanks!