Hi, I'm using rsyslog to receive logs from NetScaler v14.1, and I have an input enabled on the heavy forwarder that uses `sourcetype=citrix:netscaler:syslog`. The logs are displayed correctly in Splunk, but the fields defined in the Splunk Add-on for Citrix NetScaler v8.2.3 are not populated. Does anyone have a solution to this problem?
... View more