Citrix Configuration
Access the NetScaler administration interface using your web browser and log in using your administrator credentials.
Add a Syslog Server
Go to the Configuration tab and follow the path System > Auditing in the left-hand menu. Go to the Servers tab and click the Add button. Enter the IP address of the syslog server and the port number it uses.(UDP 514)
In Facility, specify the category of the logs (for example, local0 or local7).
Select the log level in Log Level. You can select ALL to send all logs or select specific levels such as INFO, WARNING, ERROR.
Save the settings.
Defining Syslog Actions
Go to Configuration > System > Auditing and go to the Policies tab and click the Add button. In the Name field, give this policy a name and in the Action field, select the syslog server you created earlier. In the Expression field, you can set specific filters or conditions for triggering logs, but in general you can leave this field default.
Save the settings.
Policy Binding:
After creating a Syslog policy, you need to bind this policy to the system. Go to Configuration > System > Auditing > Bindings tab and assign a policy to Global or a specific object (for example an IP address). Select the syslog policy you created earlier and perform the assignment.
Save the settings.
Log forwarding should be done in standard syslog format.
Log Format Sample
<Date and Time> <Server Name> <Session Info> : <Module> <Message Code> <Additional Info> : "<Description or Reason>"
Add Device
To make Citrix NetScaler ADC integration, it will be enough to know the ip address that the product has. When you fill in and save the necessary steps from the source addition screen with Syslog(514), the integration of your product will be completed and log flow will start. Whichever facility is selected in the log routing phase should be selected when adding the source.
Just fill in the ip section, specify the facility and the name you want to give to the resource.