We have asked our customers to forward syslog from Netscaler Service VMS (SVMs) to our Splunk syslog servers. We have tried tracroute, sending dummy data to syslog servers, but there weren't any traffics sent out at all. This is not related to Splunk, but I don't know if anyone encountered the same issues and there are any suggestions/workarounds.
Thanks.
Have you enabled the NetScaler input? And/or have you checked firewall rules?
Some additional troubleshooting tips are here:
https://docs.splunk.com/Documentation/AddOns/released/CitrixNetScaler/Troubleshoot