I have a windows forwarder deployed to collect the logs from a Xen app device, and this scripted powershell input doesn't return anything.
$SPLUNK_HOME\etc\apps\TA-XA65-Server\bin\powershell\GetXAServer65.ps1
But I can see that is ran in splunkd.log
INFO ExecProcessor - Ran script: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -command " &'C:\Program Files\Splunk\etc\apps\TA-XA65-Server\bin\powershell\GetXAServer65.ps1'" -index xenapp, took 45.94 seconds to run, 876 bytes read
Looks like a simple xenapp permission issue :
The Splunk Windows Service needs to run as a least-privileged XenApp farm administrator in order to utilize the Citrix PowerShell API. This XenApp farm administrator can be a read-only account.
We are having the same problem. I already did a huge amount of debugging but can't find the source of this issue.
The account Splunk is running as is a lokal admin and citrix admin. The message from the _internal log looks exactly like the one from mataharry, even the "876 bytes read" are identical. Were you able to solve this problem mataharry?
Looks like a simple xenapp permission issue :
The Splunk Windows Service needs to run as a least-privileged XenApp farm administrator in order to utilize the Citrix PowerShell API. This XenApp farm administrator can be a read-only account.