Splunk Enterprise

How to collect citrix events for splunk enterprise?

dbiguene
New Member

Hello everyone
I work in a citrix service and i need to collect all the citrix events with a forwarder.
My forwarder is in a citrix server and my indexer in another VM, i configure input.cong (forwarder side) to collect the events from Application with this line :
[WinEventLog://Application] and that works but i want only the citrix events, i can see the events with EventViewer, their is a "source" field in Application so is it possible to collect all the events from citrix sources like Citrix File Management ?
Something like :
[WinEventLog://Application]
source = Citrix File Management
(i tried it doesn't work)
If not, another way to do that?

Thanks

Tags (1)
0 Karma

somesoni2
Revered Legend

You'd need to set whitelist on your inputs.conf to setup your custom filter. See this link for how to do that and all available field names that you need to set (you'd need to use SourceName instead of just source in your whitelist)

http://docs.splunk.com/Documentation/Splunk/7.1.2/Data/MonitorWindowseventlogdata#Create_advanced_fi...

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...