Log transactions from a specific client in a load balancing configuration
Before you begin
-
You have deployed a Citrix ADC VPX appliance and the appliance is UP and running in your setup. For more information, see Deploy a Citrix ADC VPX instance.
-
You have a basic understanding of the load balancing feature of a Citrix ADC appliance. For more information, see:
-
You have already configured audit logging (SYSLOG or NSLOG) in the Citrix ADC appliance.
-
Enabled
userdefinedauditlogoption in the related audit action server entity. -
Bound the related audit policy to system global.
For more information about Citrix ADC audit logging, see: -
-
You have a basic understading of the Citrix ADC NITRO REST APIs. For more information, see Citrix ADC NITRO API reference.
Configuration steps
-
Create an audit message action
-
Create a rewrite policy and specify the audit message action
-
Bind the rewrite policy to the load balancing virtual server
Create an audit message action
auditmessageaction NITRO API object.
Curl request
curl -X POST -H "Content-Type: application/json" -u <username>:<password> http://<Citrix-ADC-IP-address(NSIP)>/nitro/v1/config/auditmessageaction -d '{ "auditmessageaction": { "name":"<value>", "loglevel":"<value>", "stringbuilderexpr":"<value>" }}'
Create a rewrite policy and specify the audit message action
rewritepolicy NITRO API object.
Curl request
curl -v -X POST -H "Content-Type: application/json" -u <username>:<password> http://<Citrix-ADC-IP-address(NSIP)>/nitro/v1/config/rewritepolicy -d '{ "rewritepolicy": { "name":"<value>", "rule":"<value>", "action":"<value>", "logaction":"<value>"}'
Bind the rewrite policy to the load balancing virtual server
lbvserver_rewritepolicy_binding NITRO API object.
Curl request
curl -v -X PUT -H "Content-Type:application/json" -u <username>:<password> http://<Citrix-ADC-IP-address(NSIP)>/nitro/v1/config/ lbvserver_rewritepolicy_binding -d '{ "lbvserver_rewritepolicy_binding": { "name":"<value>", "policyname":"<value>", "priority":"<value>", "gotopriorityexpression":"<value>", "bindpoint":"<value>" } }'
Sample configuration
| Steps | Curl requests | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Create an audit message action | `curl -X POST -H "Content-Type: application/json" -u nsroot:examplepassword http://192.0.0.33/nitro/v1/config/auditmessageaction -d '{"auditmessageaction": { "name":"ADT-MSG-ACN-LOG-CLIENT", "loglevel":"WARNING", "stringbuilderexpr":" ""Date & Time: "+ SYS.TIME +" | Client IP: "+ CLIENT.IP.SRC+" | Client TCP Source Port: "+CLIENT.TCP.SRCPORT+" | Client TCP Destination Port: "+CLIENT.TCP.DSTPORT+" | LB VSERVER NAME: "+HTTP.REQ.LB_VSERVER.NAME+ " | LB VSERVER IP: "+ CLIENT.IP.DST+" | Server IP: "+SERVER.IP.DST+" | Server port: "+ SERVER.TCP.DSTPORT +" | HTTP Request Method: "+ HTTP.REQ.METHOD +" | HOSTNAME: "+ HTTP.REQ.HOSTNAME +" | URL: "+ HTTP.REQ.URL +" | Response Code: "+ HTTP.RES.STATUS""}}'` |
| Create a rewrite policy and specify the audit message action | curl -v -X POST -H "Content-Type: application/json" -u nsroot:examplepassword http://192.0.0.33/nitro/v1/config/rewritepolicy -d '{ "rewritepolicy": { "name":"RWRT-POL-LOG-CLIENT", "rule":"CLIENT.IP.SRC.EQ(192.0.29.210)", "action":"NOREWRITE", "logaction":"ADT-MSG-ACN-LOG-CLIENT"}' |
|||||||||||
| Bind the rewrite policy to the load balancing virtual server | curl -v -X PUT -H "Content-Type:application/json" -u nsroot:examplepassword http://192.0.0.33/nitro/v1/config/ lbvserver_rewritepolicy_binding -d '{ "lbvserver_rewritepolicy_binding": { "name":"LBVS-1", "policyname":"RWRT-POL-LOG-CLIENT", "priority": "100", "gotopriorityexpression": "END", "bindpoint": "RESPONSE" } } ' |