Splunk® Supported Add-ons

Splunk Add-on for Citrix NetScaler

Configure Citrix NetScaler to produce data via IPFIX or syslog

The Splunk Add-on for Citrix NetScaler supports multiple data input methods. If you are only collecting data via the modular input, which pulls data from your Citrix NetScaler devices using the NITRO API, you can skip this step.

If you want to collect data about traffic on your network, authentication activity, and web server data, collect data via IPFIX as well, as this data is not available via the NITRO REST API. You also have the option to collect authentication and network data via syslog, if you prefer.

Configure Citrix NetScaler to produce IPFIX data

  1. Refer to the Citrix NetScaler documentation on "​​Configuring the AppFlow" feature and set your Splunk Enterprise data collection node as the collector.
  2. If you have not already done so, install the Splunk Stream app on your data collection node.
  3. Next, configure Splunk Stream to ingest IPFIX data on your Splunk Enterprise data collection node.

Configure Citrix NetScaler to produce syslog data

  1. Follow the instructions to "Configuring Citrix ADC appliance for audit logging" to configure syslog on a Citrix NetScaler appliance.
  2. Next, configure the syslog input on your Splunk Enterprise data collection node.
Last modified on 22 July, 2024
Upgrade the Splunk Add-on for Citrix NetScaler   Configure NITRO API inputs for the Splunk Add-on for Citrix NetScaler

This documentation applies to the following versions of Splunk® Supported Add-ons: released

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters