All Apps and Add-ons

Template for Citrix XenApp - Why is applications dashboard only showing one application?

mikaelbje
Motivator

I recently installed Template for Citrix XenApp at a customer site. We were puzzled as the applications dashboard only showed one application.

The solution can be found below. I am documenting this in case anyone else is seeing the same issue.

1 Solution

mikaelbje
Motivator

It appears that the reason for this is that the sourcetype=xenapp:65:application had all events merged into one event and we were only seeing the first entry in that event.

The solution was to deploy the following to a props.conf on the indexers


[xenapp:65:application]
SHOULD_LINEMERGE = false

This is Splunk 6.1.3. Citrix servers run Splunk Universal Forwarders. The documentation did not state that this step was necessary and there is no such stanza in the Template for Citrix XenApp App either, so I suspect that this might have worked out of the box on Splunk 6.0 but not on 6.1.3.

View solution in original post

mikaelbje
Motivator

It appears that the reason for this is that the sourcetype=xenapp:65:application had all events merged into one event and we were only seeing the first entry in that event.

The solution was to deploy the following to a props.conf on the indexers


[xenapp:65:application]
SHOULD_LINEMERGE = false

This is Splunk 6.1.3. Citrix servers run Splunk Universal Forwarders. The documentation did not state that this step was necessary and there is no such stanza in the Template for Citrix XenApp App either, so I suspect that this might have worked out of the box on Splunk 6.0 but not on 6.1.3.

ppablo
Retired

Hi @mikaelbje

Could you post the solution at the bottom as an answer and accept it to mark it as solved? It'll make this more visible as a helpful post 🙂

Patrick

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...