This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

Citrix Netscaler (Formely Netscaler ADC)

    Our Integration guide was accurate at the time of writing but vendors change things frequently! If you find errors or anything is outdated, let us know by raising a request in the Samurai MDR application and we shall get it updated.

    ProductSamurai [Local] CollectorSamurai [Cloud] Collector
    Citrix NetscalerPicture1.svg

    This guide describes the steps required to configure Citrix Netscaler to send logs to a Samurai Local Collector deployed on your network. Citrix Netscaler requires access to the Local Collector via syslog on port 514/UDP.

    To complete this Integration you will need to:

    1) From your Citrix Netscaler Appliance :

    Follow the steps outlined within the Citrix documentation:

    Use the following parameters when completing the steps:

    Field NameParameter
    Auditing TypeSYSLOG
    NameWhatever you want, however we suggest NTT_syslog_action
    ServerIPIP address of your Samurai Collector
    serverPort514
    logLevelEMERGENCY,ALERT,CRITICAL,ERROR,WARNING,NOTICE,INFORMATIONAL
    dateFormatMMDDYYYY
    transportUDP

    Table 1: Audit-log Action

    Field NameParameter
    NameWhatever you want, however we suggest NTT_syslog_policy
    ruleUse the Audit-log action you created above.

    Table 2: Audit-log Policy

    For integrations that utilize a Local Collector where we ingest syslog only, you do not need to follow specific steps in the Samurai MDR Application as we auto detect the vendor and product. The only reason you need to use the Samurai MDR Application is if you need to determine the Local Collector IP address. Of course you will still need to ensure the integration is functioning! See Integrations for more information on checking status.