Configure IPFIX inputs for the Splunk Add-on for Citrix NetScaler¶
To create an IPFIX input for the Splunk Add-on for Citrix NetScaler, you must first configure your Citrix NetScaler appliance to produce IPFIX data and send it to your collection node.
Configuration for Stream compatibility¶
Install Splunk Add-on for Stream Wire Data, Splunk App for Stream (splunk_app_stream) and Splunk Add-on for Stream Forwarders (Splunk_TA_stream) and perform the following steps in order to get IPFIX data using the Stream app.
-
Copy
citrix.xmlfrom thestream_configfolder of the add-on to the following folders:- splunk_app_stream/default/vocabularies/
- Splunk_TA_stream/default/vocabularies/
-
Copy the content of the
netflowfile from thestream_configfolder of the add-on and paste it inside thefieldslist ofsplunk_app_stream/default/streams/netflow. - Copy
streamfwd.conffrom thestream_configfolder of the add-on toSplunk_TA_stream/local. -
Change
streamfwd.confas follows:[streamfwd] ipAddr = 127.0.0.1 httpEventCollectorToken = f2060850-973b-4743-8d85-d5e89ccc28fd processingThreads = 4 netflowReceiver.0.ip = 0.0.0.0 netflowReceiver.0.port = 4739 netflowReceiver.0.decoder = netflow