Splunk Enterprise

How to collect citrix events for splunk enterprise?

dbiguene
New Member

Hello everyone
I work in a citrix service and i need to collect all the citrix events with a forwarder.
My forwarder is in a citrix server and my indexer in another VM, i configure input.cong (forwarder side) to collect the events from Application with this line :
[WinEventLog://Application] and that works but i want only the citrix events, i can see the events with EventViewer, their is a "source" field in Application so is it possible to collect all the events from citrix sources like Citrix File Management ?
Something like :
[WinEventLog://Application]
source = Citrix File Management
(i tried it doesn't work)
If not, another way to do that?

Thanks

Tags (1)
0 Karma

somesoni2
Revered Legend

You'd need to set whitelist on your inputs.conf to setup your custom filter. See this link for how to do that and all available field names that you need to set (you'd need to use SourceName instead of just source in your whitelist)

http://docs.splunk.com/Documentation/Splunk/7.1.2/Data/MonitorWindowseventlogdata#Create_advanced_fi...

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...