Jump to content

Recommended Posts

Posted

Hi All.

Does anyone have managed to export ns connections (tcp/ip connections  - client server link mapping) to splunk ? 

With the current setup, Netscaler is already sedning syslogs to Splunk, But , If you want to see which end-client IP adr is connecting to a specific vserver syslogs in SPLUNK. Do anyone have knowledge of this setup ? Or a guide how to export the ns connection table for a specific servicegroup(s) ?

BRGDS

DD

Posted

Hello @Denis Delic1709162863

 

there is no option in NetScaler do see the complete end-user-ip to backend-server-ip mapping. If you want so see such kind of information use NetScalerConsole. 

 

But you can send all the informations from NetScaler to Splunk including the TCP-Connections. Then you can try to reprocess the information to a big picture within Splunk. To send also the TCP-Connections to Splunk set this parameter within the server under System > Auditing > Syslog > Auditing > Servers    

image.thumb.png.997e62dc0da259542269120df08398c7.png

This can be a lot of traffic you will see (and generate to Splunk). For this you can filter the traffic for interesting TCP-Connections with a Policy under System > Auditing > Syslog > Auditing > Policies

 

Best regards,
Michael 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...