Log HTTP requests where the response is HTTP 5xx (server error)
-
502 Bad Gateway. The server is acting as a gateway or proxy and received an invalid response from the upstream server.
-
503 Service Unavailable. The server is currently unavailable. The servers might be overloaded or down for maintenance.
-
504 Gateway Time-out. The server is acting as a gateway or proxy and did not receive a timely response from the upstream server.
Before you begin
-
You have deployed a Citrix ADC VPX appliance and the appliance is UP and running in your setup. For more information, see Deploy a Citrix ADC VPX instance.
-
You have added a subnet IP (SNIP) address on the Citrix ADC appliance. A Citrix ADC uses a subnet IP (SNIP) address as a source IP address to proxy client connections to servers. For more information, see Configuring Subnet IP Addresses.
-
You have added an HTTP load balancing configuration in the Citrix ADC appliance. For more information about load balancing configuration, see:
-
You have already configured audit logging (SYSLOG or NSLOG) in the Citrix ADC appliance.
-
Enabled
userdefinedauditlogoption in the related audit action server entity. -
Bound the related audit policy to system global.
For more information about Citrix ADC audit logging, see: -
-
You have a basic understading of the Citrix ADC NITRO REST APIs. For more information, see Citrix ADC NITRO API reference.
Configuration steps
-
Create an audit message action
-
Create a rewrite policy and specify the audit message action
-
Bind the rewrite policy to the load balancing virtual server
Create an audit message action
auditmessageaction NITRO API object.
Curl request
curl -X POST -H "Content-Type: application/json" -u <username>:<password> http://<Citrix-ADC-IP-address(NSIP)>/nitro/v1/config/auditmessageaction -d '{ "auditmessageaction": { "name":"<value>", "loglevel":"<value>", "stringbuilderexpr":"<value>" }}'
Create a rewrite policy and specify the audit message action
rewritepolicy NITRO API object.
Curl request
curl -v -X POST -H "Content-Type: application/json" -u <username>:<password> http://<Citrix-ADC-IP-address(NSIP)>/nitro/v1/config/rewritepolicy -d '{ "rewritepolicy": { "name":"<value>", "rule":"<value>", "action":"<value>", "logaction":"<value>"}'
Bind the rewrite policy to the load balancing virtual server
lbvserver_rewritepolicy_binding NITRO API object.
Curl request
curl -v -X PUT -H "Content-Type:application/json" -u <username>:<password> http://<Citrix-ADC-IP-address(NSIP)>/nitro/v1/config/ lbvserver_rewritepolicy_binding -d '{ "lbvserver_rewritepolicy_binding": { "name":"<value>", "policyname":"<value>", "priority":"<value>", "gotopriorityexpression":"<value>", "bindpoint":"<value>" } }'
Sample configuration
| Steps | Curl requests |
|---|---|
| Create an audit message action | curl -X POST -H "Content-Type: application/json" -u nsroot:examplepassword http://192.0.0.33/nitro/v1/config/auditmessageaction -d '{"auditmessageaction": { "name":"ADT-MSG-ACN-LOG-5XX", "loglevel":"WARNING", "stringbuilderexpr": ""\"Received \" + HTTP.RES.STATUS + \" response for URL : \" + HTTP.REQ.URL.HTTP_URL_SAFE""}}' |
| Create a rewrite policy and specify the audit message action | curl -v -X POST -H "Content-Type: application/json" -u nsroot:examplepassword http://192.0.0.33/nitro/v1/config/rewritepolicy -d '{ "rewritepolicy": { "name":"RWRT-POL-LOG-5XX", "rule":"HTTP.RES.IS_SERVER_ERROR", "action":"NOREWRITE", "logaction":"ADT-MSG-ACN-LOG-5XX"}' |
| Bind the rewrite policy to the load balancing virtual server | curl -v -X PUT -H "Content-Type:application/json" -u nsroot:examplepassword http://192.0.0.33/nitro/v1/config/ lbvserver_rewritepolicy_binding -d '{ "lbvserver_rewritepolicy_binding": { "name":"LBVS-1", "policyname":"RWRT-POL-LOG-5XX", "priority": "100", "gotopriorityexpression": "END", "bindpoint": "RESPONSE" } }' |