Integration with Splunk
-
WAF violations
-
Bot violations
-
SSL Certificate Insights
-
Gateway Insights
-
NetScaler® Console Audit Logs
-
Combine all other external data sources.
-
Provide greater visibility of analytics in a centralized place.
Configure Splunk to receive data from
Setup the Splunk HTTP event collector endpoint and generate a token
-
Enable authentication between {{page.adm-product-name-short}} and Splunk.
-
Receive data through the event collector endpoint.
-
Log on to Splunk.
-
Navigate to Settings > Data Inputs > HTTP event collector and click Add new.
-
Specify the following parameters:
-
Name: Specify a name of your choice.
-
Source name override (optional): If you set a value, it overrides the source value for HTTP event collector.
-
Description (optional): Specify a description.
-
Output Group (optional): By default, this option is selected as None.
-
Enable indexer acknowledgement: {{page.adm-product-name-short}} does not support this option. We recommend not to select this option.

-
-
Click Next.
-
Optionally, you can set additional input parameters in the Input Settings page.
-
Click Review to verify the entries and then click Submit.A token gets generated. You must use this token when you add details in {{page.adm-product-name-short}}.

Install the Splunk Common Information Model
-
Log on to Splunk.
-
Navigate to Apps > Find More Apps.

-
Type CIM in the search bar and press Enter to get the Splunk Common Information Model (CIM) add-on, and click Install.

Install the CIM normalizer
-
In the Splunk portal, navigate to Apps > Find More Apps.

-
Type CIM normalization for ADM service events/data in the search bar and press Enter to get the add-on, and click Install.

Prepare a sample dashboard in Splunk
.tgz) file, use any editor (for example, notepad) to copy its contents, and create a dashboard by pasting the data in Splunk.
json file.
-
Log on to the Citrix downloads page and download the sample dashboard available under Observability Integration.
-
Extract the file, open the
jsonfile using any editor, and copy the data from the file.Note:After you extract, you get twojsonfiles. Useadm_splunk_security_violations.jsonto create the WAF and Bot sample dashboard, and useadm_splunk_ssl_certificate.jsonto create the SSL certificate insight sample dashboard. -
In the Splunk portal, navigate to Search & Reporting > Dashboards and then click Create New Dashboard.

-
In the Create New Dashboard page, specify the following parameters:
-
Dashboard Title - Provide a title of your choice.
-
Description - Optionally, you can provide a description for your reference.
-
Permission - Select Private or Shared in App based on your requirement.
-
Select Dashboard Studio.
-
Select any one layout (Absolute or Grid), and then click Create.
After you click Create, select the Source icon from the layout.
-
-
Delete the existing data, paste the data that you copied in step 2, and click Back.
-
Click Save.You can view the following sample dashboard in your Splunk.

Configure {{page.adm-product-name-long}} to export data to Splunk
-
Log on to {{page.adm-product-name-short}}.
-
Navigate to Settings > Observability Integration.
-
In the Integrations page, click Add.
-
In the Create Subscription page, specify the following details:
-
Specify a name of your choice in the Subscription Name field.
-
Select NetScaler Console as the Source and click Next.
-
Select Splunk and click Configure. In the Configure Endpoint page:
-
End Point URL – Specify the Splunk end point details. The end point must be in the https://SPLUNK_PUBLIC_IP:SPLUNK_HEC_PORT/services/collector/event format.Note:It is recommended to use HTTPS for security reasons.
-
SPLUNK_PUBLIC_IP – A valid IP address configured for Splunk.
-
SPLUNK_HEC_PORT – Denotes the port number that you have specified during the HTTP event endpoint configuration. The default port number is 8088.
-
Services/collector/event – Denotes the path for the HEC application.
-
-
Authentication token – Copy and paste the authentication token from Splunk.
-
Click Submit.
-
-
Click Next.
-
Click Add Insights and in the Select Feature tab, you can select the features that you want to export and click Add Selected.Note:If you have selected NetScaler Console Audit Logs, you can select Daily or Hourly for the frequency to export audit logs to Splunk.
-
Click Next.
-
In the Select Instance tab, you can either choose Select All Instances or Custom select, and then click Next.
-
Select All Instances - Exports data to Splunk from all the {{page.citrix-adc-generic}} instances.
-
Custom select - Enables you to select the {{page.citrix-adc-generic}} instances from the list. If you select specific instances from the list, then the data is exported to Splunk only from the selected {{page.citrix-adc-generic}} instances.
-
-
Click Submit.Note:The data for the selected insights gets pushed to Splunk immediately after the violations are detected in {{page.adm-product-name-short}}.
-
View dashboards in Splunk
-
In Splunk, click Search & Reporting.
-
In the search bar:
-
Type
sourcetype="bot"orsourcetype="waf"and select the duration from the list to view bot/WAF data. -
Type
sourcetype="ssl"and select the duration from the list to view the SSL certificate insights data. -
Type
sourcetype="gateway_insights"and select the duration from the list to view the Gateway insights data. -
Type
sourcetype= "audit_logs"and select the duration from the list to view the audit logs data.
-