All Apps and Add-ons

Splunk for Citrix Netscaler with Appflow and Splunk Add-on for IPFIX: Why is the host showing up as the Splunk Intermediate Forwarder?

gn694
Communicator

I have the Splunk Add-on for IPFIX installed along with the App for Citrix Netscaler.
We have our netscalers set up to forward data to a pair of Intermediate Forwarders, which sends it to our Indexers.

All entries are showing up where the value of Host is the name of the Intermediate Forwarder it came in through.
When configuring the IPFIX input, there is an option for Host. When the App for Citrix Netscaler created the IPFIX input it specified the Intermediate Forwarder as the Host. I removed the Intermediate Forwarder name and left the value of Host empty in the input configuration, and the host is still showing up as the name of the Intermediate Forwarder.

How can I set the Host to be the actual name of the Netscaler device? Basically I'm trying to get the functionality of host = DNS lookup like you can set for a UDP or TCP input.

thankx

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

Hi, you may have to force that in local/props.conf.

0 Karma
Get Updates on the Splunk Community!

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...