NetScaler instances generate AppFlow records and are a central point of control for all application traffic in the data center. IPFIX and Logstream are the protocols that transport these AppFlow records from NetScaler instances to NetScaler Console. For more information, see
AppFlow.
-
IPFIX is an open Internet Engineering Task Force (IETF) standard defined in RFC 5101. IPFIX uses UDP protocol which is unreliable transport protocol used for data flow in one direction. Since IPFIX uses UDP protocol, adhering to IPFIX standard results in processing more resources in NetScaler Console.
-
Logstream is a Citrix-owned protocol that is used as one of the transport modes to efficiently transfer the analytics log data from NetScaler instances to NetScaler Console. Logstream uses reliable TCP protocol and requires lesser resources in processing the data.
For NetScaler between 11.1 Build 47.14 and 11.1 Build 62.8, Logstream is the default transport mode for enabling Web Insight (HTTP) and IPFIX is the only transport mode for enabling other insights. For NetScaler version starting from 12.0 to latest version, you can select either Logstream or IPFIX as the transport mode.