Configure Citrix NetScaler


  1. In the Configuration utility, expand SystemAuditing, then click syslog.
  2. Click the Servers tab, then click Add.
    1. In the Name field, enter the name of the syslog server (for example, McAfee Event Receiver), then select syslog from the Auditing Type list.
    2. In the IP Address field, enter the IP address of the McAfee Event Receiver.
    3. In the Port field, enter the port number used for syslog by the McAfee Event Receiver (default is 514).
    4. In the Log Levels group, select ALL to send all logs to the McAfee Event Receiver.
      Note: Individual levels can be selected as needed.
    5. Click Create, then click Close.
  3. Click the Policies tab to add audit policies, then click Add.
    1. In the Name field, enter a name for the policy (for example, McAfee ESM).
    2. Select SYSLOG in the Auditing Type list, then select the McAfee Event Receiver server name in the Server list.
    3. Click Create, then click Close.
  4. Click Global Bindings, click Insert Policy, and select the policy name that you created.
  5. Click OK.