Splunk Search

Splunk TA for Citrix NetScaler

edwardrose
Contributor

Hello All,

I installed the Splunk Add-on for Citrix NetScaler

https://splunkbase.splunk.com/app/2770/

And I do not see the field extractions unless I am in the Add-on in the UI. So if I bring up search and reporting and then do a search on the NetScaler index I would expect to see all the extracted fields from the Add-on.

View from search and reporting
alt text

View from a search under the add-on
alt text

So what am I missing that would allow me to see all the fields in other apps? I have set the permissions to be readable by everyone and sharing set to all apps. So I am not sure what is wrong here.

thanks
ed

0 Karma

edhealea
Path Finder

edwardrose Did you ever get an answer to this question? I am having a similar issue.

0 Karma

AlexHauptner
Engager

Hey,

it looks like a permission issue:

Go to "Manage Apps" and find the "Splunk Add-On for Citrix NetScaler", then click on "Permissions" and below change it from "This app only" to "All apps"

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...