All Apps and Add-ons

Where does Splunk for Citrix NetScaler with AppFlow need to be installed in a distributed search environment and where can I specify a custom index?

gn694
Communicator

In a distributed environment, where does Splunk for Citrix NetScaler with AppFlow need to be installed other than the Search Heads? Does it need to be installed on Intermediate Forwarders and/or Indexers?

Also, where can I specify an index other than netscaler to use for whatever things this app is attempting to index? We have a standard for the naming of indexes where they are all prefixed with a group name according to who is allowed access to the index. So I want to use an index named <group1>-netscaler. We already have this custom index created and configured for IPFIX inputs, but our indexers have been complaining since we installed this app "received event for unconfigured/disabled/deleted index='netscaler'"

I see in /default/macros.conf there is a stanza:
[ns_index]
definition = index=netscaler

Could I just create a macros.conf in /local and add the following (or would there be more involved to this...)
[ns_index]
definition = index=<group1>-netscaler

(As far as populating dashboards, I see in /default/eventtypes.conf there is a netscaler event type configured as index=netscaler. I have added an eventtypes.conf to the local folder setting it to be index=<group1>-netscaler.)

thank you

0 Karma

jconger
Splunk Employee
Splunk Employee

Depends on where you are sending your data from your NetScaler(s). If you are sending to the indexer(s), the Splunk_TA_Citrix-NetScaler needs to go on your indexers. If you are sending to an intermediate forwarder, then put it there instead.

You can modify the macros.conf and eventtypes.conf to specify your custom index.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...