How do I get data into Splunk for XenApp 6.0?

New Member


I have a XenApp 6 farm. I have installed the Universal forwarder and configured that one.

I have installed the Splunk for Xen App addon on the splunk console.

I have also tried copying the modules TA-XA60-Server to the etc/apps forlder on the universal forwarder client.

I only get logs like eventlogs to the splunk console. What do I need to do to get all the other Citrix Data to my Splunk console?

0 Karma


You probably need need to set the execution policy for powershell to allow it to run the scripts. you can check in your var/log/splunk/splunkd.log file and see the errors, if any, when trying to run powershell scripts.

open powershell and run the following command "Set-ExecutionPolicy RemoteSigned". This will let the powershell script run. You may have to run the command in 32 or 64 bit powershell depending on what version splunk is trying to kick the script off with. I think mine was using the 64 bit.

I also noticed that with the XenDesktop app that the perfmon collection is not working with the Universal Forwarder V5. If you are using V5 try using the 4.3.4 UF and see if your permon data starts coming about 5 minutes after you first start seeing data come in from the other sources.

0 Karma

Splunk Employee
Splunk Employee

The path reference to the TA in the inputs.conf for v6 references the TA folder name as TA-XA6-Server. This is likely an artifact of naming prior to 6.5 support. If you change the folder name for the TA all of your inputs should start sending correctly.

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!