Deployment Architecture

Netscaler AppFlow Independent Forwarder



I am attempting to get some analytics from the Netscaler into Splunk via an Independent Forwarder using AppFlow policies on the Netscaler.

I have followed this document to install and configure the Independent Forwarder:

I then followed this one to setup the above Independent Forwarder so it could receive the IPFIX data from the Netscaler AppFlow policy:

When I applied the Netscaler AppFlow policy to a virtual server data was not coming through. I tail -f the streamfwd.log and it was indicating that it did not have have the required templates to decode the netflow. I amended the template refresh interval on the Netscaler to 60 seconds and sure enough, not too long after that, the data was making its way into the specified index.

When I search the index where the data is going to (index="netscaler"), it seems the Netflow elements are not being decoded. I have basic information such as source ip and destination ip, but all other data, I suspect, is locked away under the netflow_elements: field, which contains no human readable data.
This document says to set the source type to citrix:netscaler:ipfix, and i did on the httpinput inputs.conf, but this appears to have no effect, as the source on the aforementioned events is simply stream:netflow.

Any assistance would be greatly appreciated.


Labels (1)
0 Karma



Another alternative to ingest Netscaler AppFlow (IPFIX) into Splunk is with our product - NetFlow Optimizer (We are Splunk Technology Partner). You can download it and get 60 day free license by visiting

Please contact us directly at if you have any questions or need help.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...