Citrix ADC Integration Guide🔗
Citrix ADC should be configured to send logs via syslog to the Taegis™ XDR Collector. Please follow the instructions in Citrix’s documentation to configure audit logging.
Connectivity Requirements🔗
| Source | Destination | Port/Protocol |
|---|---|---|
| Citrix ADC | XDR Collector (mgmt IP) | UDP/514 |
Important
The date format for NetScaler logs must be set as MM/DD/YYYY. The format of DD/MM/YYYY is not supported for proper ingest.
Important
The data source must be configured to emit timestamps with an explicit offset or in UTC to ensure that XDR reports the correct time zone. For more information, see Integration Event Time and Time Zone Handling.
Data Provided from Integrations🔗
| Normalized Data | Out-of-the-Box Detections | Vendor-Specific Detections | |
|---|---|---|---|
| Citrix ADC | Management | Auth, HTTP, Netflow |
Note
XDR detectors are not guaranteed to be triggered, even if a data source's logs are normalized to a schema associated with a given detector. However, you can create Custom Detection Rules to generate detections based on normalized data from a data source.
Configuration Instructions🔗
To configure Citrix ADC to send logs to Secureworks® Taegis™ XDR via syslog, follow the instructions provided by Citrix to configure audit log policies.
Ensure you complete the following fields with the correct values:
- Server IP — The IP address of the XDR Collector
- Protocol — UDP
- Port — 514
Note
Citrix ADC events are normalized as XDR Sensor Type Netscaler.