Troubleshoot the Splunk Add-on for Citrix NetScaler¶
For troubleshooting tips that you can apply to all add-ons, see Troubleshoot add-ons in Splunk Add-ons. For additional resources, see Support and resource links for add-ons in Splunk Add-ons.
HTTP Error: 407, Proxy Authentication Required¶
If you have an HTTP proxy configured, you are using unencrypted communication, and you get this error, go to Configuration, and then Proxy, and change the Proxy Type to http_no_tunnel.
Citrix Netscaler supported syslog format¶
The following format of Citrix Netscaler syslogs is supported:
<time-stamp> <ns-name> <packet-engine-name>:<> <event-source> <event-name> <event-id> 0 :<syslog-message>
The Splunk add-on for Citrix Netscaler does not support this format when collecting events from the Stream app, as those events have the stream:netflow sourcetype.
Configure logging level¶
The Splunk Add-on for Citrix NetScaler allows you to configure logging levels in the configuration UI or in splunk_ta_citrix_netscaler_settings.conf. Allowed log levels are DEBUG, INFO, and ERROR. The default is INFO.
Perform the following steps to configure logging using the UI:
- Go to Splunk Web on your data collection node.
- Access the Splunk Add-on for Citrix NetScaler UI.
- From the configuration menu, select Configuration > Logging.
- Choose a log level and select Save.