Application Firewall logs are not displayed on the Command Center Application Firewall dashboard.
To resolve this issue disable CEF logging on NetScaler settings.
CEF logging was enabled in the Application Firewall settings and that was the reason why Application Firewall records were not coming onto the dashboard.
We can see the event in the NetScaler ns.log file :
Aug 6 16:18:24 <local0.info> 192.168.31.21 08/06/2015:16:18:24 waf01 0-PPE-0 : APPFW APPFW_FIELDCONSISTENCY 30385582 0 : CEF:0|Citrix|NetScaler|NS10.1|APPFW|APPFW_FIELDCONSISTENCY|6|src=X.X.X.87 spt=25968 method=OPTIONS request=https://mail.got.com.tr/Microsoft-Server-ActiveSync?Cmd\=OPTIONS&User\=John%Snow&DeviceId\=SEC1A7516082D449&DeviceType\=Longclaw msg=Field consistency check failed for field "" cn1=25456906 cn2=32871710 cs1=John_Owa_Prof cs2=PPE0 cs3=M2a7QubQDCayIe4lSv7ZngdfEtYA000 cs4=ALERT cs5=2015 act=not blocked
We can see the same event on the Command Center alert_audit.txt which confirms that the event came till the Command Center server :
Update: At Thu Aug 06 16:15:58 EEST 2015. Major from Major. Alert: CEF:0|Citrix|NetScaler|NS10.1|APPFW|APPFW_FIELDCONSISTENCY|6|src=X.X.X.87:appfwFieldConsistency192.168.31.21 : CEF:0|Citrix|NetScaler|NS10.1|APPFW|APPFW_FIELDCONSISTENCY|6|src=X.X.X.87 spt=25968 method=OPTIONS request=https://mail.got.com.tr/Microsoft-Server-ActiveSync?Cmd\=OPTIONS&User\=John%Snow&DeviceId\=SEC1A7516082D449&DeviceType\=Longclaw msg=Field consistency check failed for field "" cn1=25456906 cn2=32871710 cs1=John_Owa_Prof cs2=PPE0 cs3=M2a7QubQDCayIe4lSv7ZngdfEtYA000 cs4=ALERT cs5=2015 act=not blocked
Again we can see a trap received by Command Center from NetScaler for this event in the FaultOut.txt :
-> trap from x.x.x.242 vectVarBind=[.1.3.6.1.2.1.1.3.0: 169 days, 3 hours, 47 minutes, 32 seconds., .1.3.6.1.6.3.1.1.4.1.0: .1.3.6.1.4.1.5951.1.1.0.92, .1.3.6.1.4.1.5951.4.1.10.2.25.0: CEF:0|Citrix|NetScaler|NS10.1|APPFW|APPFW_FIELDCONSISTENCY|6|src=X.X.X.87 spt=25968 method=OPTIONS request=httrequest=https://mail.got.com.tr/Microsoft-Server-ActiveSync?Cmd\=OPTIONS&User\=John%Snow&DeviceId\=SEC1A7516082D449&DeviceType\=Longclaw msg=Field consistency check failed for field "" cn1=25456906 cn2=32871710 cs1=John_Owa_Prof cs2=PPE0 cs3=M2a7QubQDCayIe4lSv7ZngdfEtYA000 cs4=ALERT cs5=2015 act=not blocked, .1.3.6.1.4.1.5951.4.1.1.2.0: 192.168.31.21
With a trace we could see that the syslog events were coming till Command Center Server. On the Command Center server logs were visible under Syslog > Complete view.
Also if we check the logs on Command Center we can see them recorded in Fault.out and alert_audit.txt.