Document toolboxDocument toolbox

network.citrix

Check the reference vendor documentation here.

Introduction

The tags beginning with network.citrix identify events generated by Citrix (formally known as Citrix NetScaler)

Valid tags and data tables

The full tag must have 4 levels. The first two are fixed as network.citrix. The third level identifies the type of events sent, and the fourth level indicates the event subtype.

If you need to parse any events with a subtype that is not included in the table below, please contact us so we can analyze your case and create a dedicated parser.

Technology

Brand

Type

Subtype

Technology

Brand

Type

Subtype

network

citrix

adc



  • aaa

  • aaatm

  • api

  • cli

  • event

  • gui

  • ica

  • snmp

  • ssllog

  • sslvpn

  • tcp

  • other

netscaler

snmp

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Citrix ADC

network.citrix.adc

network.citrix.adc

network.citrix.adc.aaa

network.citrix.adc.aaa

network.citrix.adc.aaatm

network.citrix.adc.aaatm

network.citrix.adc.api

network.citrix.adc.api

network.citrix.adc.appfw

network.citrix.adc.appfw

network.citrix.adc.cli

network.citrix.adc.cli

network.citrix.adc.console

network.citrix.adc.console

network.citrix.adc.event

network.citrix.adc.event

network.citrix.adc.gui

network.citrix.adc.gui

network.citrix.adc.ica

network.citrix.adc.ica

network.citrix.adc.nswl

network.citrix.adc.nswl

network.citrix.adc.other **

network.citrix.adc.other

network.citrix.adc.snmp

network.citrix.adc.snmp

network.citrix.adc.ssllog

network.citrix.adc.ssllog

network.citrix.adc.sslvpn

network.citrix.adc.sslvpn

network.citrix.adc.tcp

network.citrix.adc.tcp

Citrix NetScaler

network.citrix.netscaler.event

network.citrix.netscaler.event

network.citrix.netscaler.misc

network.citrix.netscaler.misc

network.citrix.netscaler.snmp

network.citrix.netscaler.snmp

network.citrix.netscaler.tcp

network.citrix.netscaler.tcp

** For any other network.citrix.adc logs, use network.citrix.adc.other table.

How is the data sent to Devo?

Logs generated by Cisco must be sent to the Devo platform via the Devo Relay to secure communication. See the required relay rule below:

  • Source port → Set as required

  • Source datadefault (\S+)

  • Target tagnetwork.citrix.adc.\\d1

  • Target message\\d0

Table structure

These are the fields displayed in these tables: