All Apps and Add-ons

Oracle WebLogic App for Splunk: Which add-on do I use to monitor WebLogic logs?

ahmedhassanean
Explorer

Dears,

I have installed Oracle WebLogic App for Splunk and navigate to add-ons and found below
function1_weblogicserver_eventgen Function1_WLS_App Function1_WLS_Managed_win_TA SA-Eventgen
Function1_WLS_Admin_nix_TA Function1_WLS_IDX_SH_TA Function1_WLS_nix_performance_TA
Function1_WLS_Admin_win_TA Function1_WLS_Managed_nix_TA Function1_WLS_win_performance_TA

I need to know if Splunk can monitor WebLogic logs or not, and if, yes which add-on I have to use?

0 Karma

tsweet_splunk
Splunk Employee
Splunk Employee

For Linux Weblogic Server:
Function1_WLS_Admin_nix_TA
Function1_WLS_Managed_nix_TA

For Windows WebLogic Server:
Function1_WLS_Admin_win_TA
Function1_WLS_Managed_win_TA

Look at the inputs.conf on each of these Admin/Manged files to verify the location is correct (this only monitors in the default logging location)

On Search Heads and Indexers:
Function1_WLS_IDX_SH_TA

On Search Head:
Function1_WLS_App

ahmedhassanean
Explorer

what i am trying to say that i have log files of Weblogic that contain below messages and i want to know if this addon contain extraction for it or not
weblogic.kernel.Default (self-tuning)

0 Karma

anshu
Path Finder

Hi Ahmed, what is the path to the log file that you find the "weblogic.kernel.Default" messages in?

The add-ons can monitor log files from Web Logic. As tsweet said, the best thing to do is look at the inputs.conf configuration in the add-ons and determine if the log files you want to monitor are in those paths.

Below are two monitor stanzas from the "Function1_WLS_Managed_nix_TA" inputs.conf file as an example:

[monitor:///opt/./.../user_projects/domains/*/servers/*/logs/*.log]

[monitor:///opt/./.../user_projects/domains/*/servers/*/logs/access.log]
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...