The current Netscaler guidance is that logs should be exported via HEC. However, it seems like the app doesn't have a sourcetype for HEC. Any guidance on that?
The recommended way of receiving Netscaler events is by Splunk's own addon https://docs.splunk.com/Documentation/AddOns/released/CitrixNetScaler/About
You might want to try to use the same sourcetype but I have no idea what the format will be if you do it according to Netscaler's docs.