I have configured Splunk for Citrix Netscaler on a Ubuntu linux box and the accompanying ipfix/appflow add on and I am receiving ipfix events. The problem is that most of the fields in the Splunk for Citrix Netscaler Appflwo section remain empty. Any advice on this?
Hi, have you tried this? http://docs.splunk.com/Documentation/AddOns/latest/IPFIX/ConfigureEnterpriseInformationElements