citrix / citrix/cc-system-log-addon-for-splunk

Not pulling logs into Splunk index

Open
#4 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
2
Forks
1
PR merge metrics
No merged PRs in 30d

Description

I have this add-on configured in Splunk and I can see the API Key being accessed every 30 minutes in the Citrix Cloud console, but it never pulls any logs. There are no errors in the citrix log that is created on the Splunk server. Even the date on the GET /systemlog/records URL updates to the last date where logs were created in the Citrix System Log in the Citrix Cloud Console. This is setup on Splunk Enterprise 8.2.1.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reproducing the 30-minute collection cycle in Splunk Enterprise 8.2.1 and inspect the response from GET /systemlog/records alongside the citrix log on the Splunk server. Determine why records are not being pulled despite API key access, and confirm completion when Citrix System Log entries are indexed without errors.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
observability
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.