All Apps and Add-ons

Citrix XenApp Index

aaronkorn
Splunk Employee
Splunk Employee

Are there any indexs that we need to create for the Citrix XenApp Application? We installed the app to the splunk indexer and installed the UF onto the XenApp Servers. Also, does anyone know a link where some good documentation can be found on this app?

0 Karma
1 Solution

bsonposh
Communicator

Verify that you have the TA (Collector) and the splunkforwarder on the XenApp Servers (ta-xa-broker needs to be on one and ta-xa-server needs to be on all the XenApp servers) and make sure that PowerShell execution policy is set to remotesigned.

http://technet.microsoft.com/en-us/library/ee176961.aspx

View solution in original post

0 Karma

aaronkorn
Splunk Employee
Splunk Employee

The only thing that appears to be missing still is the Top 10 IP Clients, Top Client Version, and all ICA Session Info. We checked the .info files and there was another issue with naming where it stated TA-XA65 instead of TA-XA5 but that did not fix the issue.

0 Karma

aaronkorn
Splunk Employee
Splunk Employee

Yes we are still not able to see this data.

0 Karma

bsonposh
Communicator

Is this still a problem?

0 Karma

aaronkorn
Splunk Employee
Splunk Employee

Awesome! The TA-XA-Server\bin *.path was the issue. One I replaced "Broker" with "Server" everything is now showing up. Thanks!

0 Karma

bsonposh
Communicator

Verify that you have the TA (Collector) and the splunkforwarder on the XenApp Servers (ta-xa-broker needs to be on one and ta-xa-server needs to be on all the XenApp servers) and make sure that PowerShell execution policy is set to remotesigned.

http://technet.microsoft.com/en-us/library/ee176961.aspx

0 Karma

bsonposh
Communicator

You can check the inputs.conf and verify that is correct but if you are running on 4.5 I believe there is a bug in the *.path files on the TA.

In TA-XA-Server\bin*.path files make sure the script path is to the Server TA and not the Broker TA.

The License stuff is not a requirement but the licensing dashboard will not populate without it.

0 Karma

aaronkorn
Splunk Employee
Splunk Employee

Also, we have not applied the TA-CitrixLicensing portion. Is this needed? We do not want to deploy that quite yet as we are testing this in dev and the certificate server is also used for production and testing environments.

0 Karma

aaronkorn
Splunk Employee
Splunk Employee

I believe we are on 4.5 and the ta-xa-server is deployed everywhere. I have not tried to run the scripts manually but I can give that a shot. I also noticed that the sourcetypes exist but they are being sent to the main index. I am going to try to configure the inputs.conf file on the citrix boxes. Or would that not help?

Thanks!

0 Karma

bsonposh
Communicator

What version of XenApp? Is the collector (ta-xa-server) deployed everywhere? What happens if you run the PowerShell scripts manually? Any errors in the $Splunk_Home/var/log/splunk/splunkd.log

0 Karma

aaronkorn
Splunk Employee
Splunk Employee

Thanks. It looks like powershell scripts are able to run as we have some data from scripts in splunk. We are missing several sourcetypes which is why many of the dashboard panels are not coming back with any data. We are missing the xenapp, xa_sessions, and Perfmon:LogicalDisk to name a few.

0 Karma

bsonposh
Communicator

The indexes should be create by the app itself. If you have separate indexers and search heads just make sure the dashboard app is on both.

As for the documentation we are doing the official release of this app at Synergy Barcelona and that will include full documentation.

0 Karma

aaronkorn
Splunk Employee
Splunk Employee

Thank you. It appears that all the indexes are created but we are still not gathering any session information.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...