Refine your search:

In the new Splunk for Citrix XenApp app, I see index definitions, but no documentation on how to get data in, what data is expected as what sourcetypes, etc. I need to instruct the forwarders on what data to collect, what to sourcetype it as, and what index to put it in. Did I miss a readme in there somewhere?

asked 18 May '12, 07:16

Jason's gravatar image

Jason
3.6k71075
accept rate: 43%

edited 18 May '12, 07:17


5 Answers:

There are "TA" (Technology Add-ons) included with the application. These are located at <app>appserveraddons.

  • TA-XA**-Broker goes on the ZDC
  • TA-XA**-Server goes on each XenApp Server
  • TA-CitrixLicensing-1 goes on the Citrix Licensing server

You can use deployment server to handle deployment or you can do it manually.

There are docs forthcoming.

link

answered 18 May '12, 08:00

bsonposh's gravatar image

bsonposh
588110
accept rate: 40%

I'm looking to do this also but unsure of the steps. Does a universal forwarder need to reside on each XenApp server? How should it be configured and where should the TA files reside on the XenApp server too?

link

answered 21 May '12, 23:31

bwindham's gravatar image

bwindham
311
accept rate: 0%

Yes... the UF needs to be on all XenApp servers and the TA's deployed.

TA-XA-Broker goes on one or two XenApp servers... preferably not one that supports users. TA-XA-Server goes on ALL XenApp servers.

(21 May '12, 23:45) bsonposh

bsonposh, Thanks for the quick reply and pardon my ignorance, but where do the TA's need to be deployed exactly on the XA server? Under etc/apps? And as for the TA-60-Server, do I copy the whole directory from $splunkhome/splunk/etc/apps/SpunkForXenApps/appserver/addon to the location (???) on XA? Does anything else need to be configured on XenApp Server application to send data? Thanks in advance.....I really want to get this going!

link

answered 22 May '12, 00:16

bwindham's gravatar image

bwindham
311
accept rate: 0%

Yes, the TA-* apps will go into etc/apps to become part of Splunk's active configuration. Try to ask questions as new questions on the site, not in answers to an existing question.

(24 May '12, 07:18) Jason

Thanks for sharing. I've done all the Splunk App & TA-XA5 installed on Citrix server Xenapp5 but no data being sent to splunk server. Can anyone advise? many thanks.

attached some of error capture from splunkd. 09-07-2012 14:33:53.437 +0800 ERROR WinEventLogInputProcessor - processLogChannel: Failed to checkpoint for channel='Setup' 09-07-2012 14:33:53.437 +0800 INFO WinEventLogInputProcessor - main-thread: It seems like the Windows Event Log channel 'Setup' has been reset 09-07-2012 14:34:43.828 +0800 ERROR ExecProcessor - message from "C:WindowsSystem32WindowsPowerShellv1.0powershell.exe -command " &'C:Program FilesSplunkUniversalForwarderetcappsTA-XA5-BrokerbinpowershellGetXAServerLoad5.ps1'" -index xenapp" The term 'C:Program FilesSplunkUniversalForwarderetcappsTA-XA5-Brokerbin 09-07-2012 14:34:43.828 +0800 ERROR ExecProcessor - message from "C:WindowsSystem32WindowsPowerShellv1.0powershell.exe -command " &'C:Program FilesSplunkUniversalForwarderetcappsTA-XA5-BrokerbinpowershellGetXAServerLoad5.ps1'" -index xenapp" powershellGetXAServerLoad5.ps1' is not recognized as a cmdlet, function, opera 09-07-2012 14:34:43.828 +0800 ERROR ExecProcessor - message from "C:WindowsSystem32WindowsPowerShellv1.0powershell.exe -command " &'C:Program FilesSplunkUniversalForwarderetcappsTA-XA5-BrokerbinpowershellGetXAServerLoad5.ps1'" -index xenapp" ble program, or script file. Verify the term and try again.

link

answered 06 Sep '12, 23:42

kelvinlow's gravatar image

kelvinlow
211
accept rate: 0%

Hi, I cant see any data populated to Splunk server even though Indexes are created. Just to curios, am i suppose to create datasources?

link

answered 09 Sep '12, 23:48

kelvinlow's gravatar image

kelvinlow
211
accept rate: 0%

Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

Asked: 18 May '12, 07:16

Seen: 1,526 times

Last updated: 09 Sep '12, 23:48

Copyright © 2005-2012 Splunk Inc. All rights reserved.