All Apps and Add-ons

Xen app forwarder scripted input fails to collect logs

mataharry
Communicator

I have a windows forwarder deployed to collect the logs from a Xen app device, and this scripted powershell input doesn't return anything.

$SPLUNK_HOME\etc\apps\TA-XA65-Server\bin\powershell\GetXAServer65.ps1

But I can see that is ran in splunkd.log

INFO ExecProcessor - Ran script: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -command " &'C:\Program Files\Splunk\etc\apps\TA-XA65-Server\bin\powershell\GetXAServer65.ps1'" -index xenapp, took 45.94 seconds to run, 876 bytes read

1 Solution

yannK
Splunk Employee
Splunk Employee

Looks like a simple xenapp permission issue :

The Splunk Windows Service needs to run as a least-privileged XenApp farm administrator in order to utilize the Citrix PowerShell API. This XenApp farm administrator can be a read-only account.

see http://docs.splunk.com/Documentation/XenApp/1.0/DeployXenApp/Otherdeploymentconsiderations#Permissio...

View solution in original post

fbl_itcs
Path Finder

We are having the same problem. I already did a huge amount of debugging but can't find the source of this issue.

The account Splunk is running as is a lokal admin and citrix admin. The message from the _internal log looks exactly like the one from mataharry, even the "876 bytes read" are identical. Were you able to solve this problem mataharry?

0 Karma

yannK
Splunk Employee
Splunk Employee

Looks like a simple xenapp permission issue :

The Splunk Windows Service needs to run as a least-privileged XenApp farm administrator in order to utilize the Citrix PowerShell API. This XenApp farm administrator can be a read-only account.

see http://docs.splunk.com/Documentation/XenApp/1.0/DeployXenApp/Otherdeploymentconsiderations#Permissio...

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...