Splunk Enterprise

How to collect citrix events for splunk enterprise?

dbiguene
New Member

Hello everyone
I work in a citrix service and i need to collect all the citrix events with a forwarder.
My forwarder is in a citrix server and my indexer in another VM, i configure input.cong (forwarder side) to collect the events from Application with this line :
[WinEventLog://Application] and that works but i want only the citrix events, i can see the events with EventViewer, their is a "source" field in Application so is it possible to collect all the events from citrix sources like Citrix File Management ?
Something like :
[WinEventLog://Application]
source = Citrix File Management
(i tried it doesn't work)
If not, another way to do that?

Thanks

Tags (1)
0 Karma

somesoni2
Revered Legend

You'd need to set whitelist on your inputs.conf to setup your custom filter. See this link for how to do that and all available field names that you need to set (you'd need to use SourceName instead of just source in your whitelist)

http://docs.splunk.com/Documentation/Splunk/7.1.2/Data/MonitorWindowseventlogdata#Create_advanced_fi...

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...