All Apps and Add-ons

Xen app forwarder scripted input fails to collect logs

mataharry
Communicator

I have a windows forwarder deployed to collect the logs from a Xen app device, and this scripted powershell input doesn't return anything.

$SPLUNK_HOME\etc\apps\TA-XA65-Server\bin\powershell\GetXAServer65.ps1

But I can see that is ran in splunkd.log

INFO ExecProcessor - Ran script: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -command " &'C:\Program Files\Splunk\etc\apps\TA-XA65-Server\bin\powershell\GetXAServer65.ps1'" -index xenapp, took 45.94 seconds to run, 876 bytes read

1 Solution

yannK
Splunk Employee
Splunk Employee

Looks like a simple xenapp permission issue :

The Splunk Windows Service needs to run as a least-privileged XenApp farm administrator in order to utilize the Citrix PowerShell API. This XenApp farm administrator can be a read-only account.

see http://docs.splunk.com/Documentation/XenApp/1.0/DeployXenApp/Otherdeploymentconsiderations#Permissio...

View solution in original post

fbl_itcs
Path Finder

We are having the same problem. I already did a huge amount of debugging but can't find the source of this issue.

The account Splunk is running as is a lokal admin and citrix admin. The message from the _internal log looks exactly like the one from mataharry, even the "876 bytes read" are identical. Were you able to solve this problem mataharry?

0 Karma

yannK
Splunk Employee
Splunk Employee

Looks like a simple xenapp permission issue :

The Splunk Windows Service needs to run as a least-privileged XenApp farm administrator in order to utilize the Citrix PowerShell API. This XenApp farm administrator can be a read-only account.

see http://docs.splunk.com/Documentation/XenApp/1.0/DeployXenApp/Otherdeploymentconsiderations#Permissio...

Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...