Skip to content

Integrate NetScaler ADC

You can integrate NetScaler ADC (formerly Citrix ADC) with Sophos XDR so that it sends data to Sophos for analysis. The integration uses a data collector, which receives third-party data and sends it to the Sophos Data Lake.

Key steps

The key steps in a NetScaler ADC integration are as follows:

  • Install and configure a data collector if you haven't already done so.
  • Configure NetScaler ADC to send data to the data collector.

Requirements

The following is required for NetScaler ADC configuration:

  • Check the requirements for the data collector you're using by reviewing the guides at Data collectors.

Add a NetScaler ADC integration

To integrate NetScaler ADC, you must first install a Sophos XDR data collector, then configure NetScaler to send logs to it.

Install and configure a data collector

NetScaler ADC must be configured to send logs to the Sophos XDR data collector. Logs are filtered and correlated in real-time for various security event observations. Go to Data collectors and follow the guide for creating a data collector if you haven't already done so.

Configure logging and enable monitoring

When the data collector is ready, you can configure NetScaler ADC to send us data.

To set up event forwarding via syslog, do as follows:

  1. Follow the steps in NetScaler's own guide: Configuring NetScaler appliance for audit logging.
  2. Be sure the configured IP address matches the Sophos XDR data collector's server IP address.

Your NetScaler ADC data should now appear in the Sophos Data Lake after validation.

Configuration notes

Keep the following in mind during NetScaler ADC configuration:

  • The date format for NetScaler logs must be set as MM/DD/YYYY. The DD/MM/YYYY format isn't supported for proper ingestion.
  • Data must be in UTC for the event time in Sophos XDR to be accurate.
  • You can configure multiple instances of NetScaler to send data to Sophos via the same data collector. After you finish integration, repeat the steps in this section for your other instances of NetScaler.

Additional resources

For more information on configuring NetScaler ADC, see the following documents: