All Apps and Add-ons

Are there any special settings to enable on a citrix netscaler device?

mctester
Communicator

We have set up UDP inputs for syslog data on splunk indexers. We have set up a load balancing pool on a citrix netscaler to forward data to splunk. We are getting messages in splunk from the devices, but they all say "UDP Data" and nothing else.

This is consistent for all devices we are trying to forward via the netscaler. I'm assuming it is a persistence setting or something on the netscaler, but am not sure. Data sent directly to splunk is actual syslog data, is indexed properly and is successfully in searches.

I realize that this is not necessarily an issue with Splunk but I'm hopeful that one of the many Admins out there has worked with these devices before and can provide some helpful advice.

thanks

Tags (1)

lukeh
Contributor

We were seeing the same problem with NetScaler NS9.2: Build 48.6.cl - however we discovered that sending the syslog events to Splunk via the internal interface on the Netscaler resulted in garbled events, however sending via the external interface resulted in sweet, sweet syslog love...

All the best,

Luke 🙂

0 Karma

sylvainc
Engager

Hi

I'm an SE at Citrix, specialist on NetScaler.
Could you post your NS config and a schema of what you want to do (clients, Vserver, servers)

Thanks in advance

regards

Sylvain

Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...