All Apps and Add-ons

Splunk Add-On for Tomcat: Search Head not working

TitanAE
New Member

I deployed the Tomcat Add-On for Splunk. It's currently running on both my indexer and search head.

It's working without issue on the indexer. But it's not displaying the data in the correct format on the search head. And I'm not sure what to do to fix this issue:

I've checked to make sure the data is in the correct format for the forwarder
I've checked the permissions on the server, they're correct
I've recreated my environment to spec...

I've done everything except get the bloody thing to work. I need help.

0 Karma

mbagali_splunk
Splunk Employee
Splunk Employee

@TitanAE,

This add-on has 3 logs that are located at $SPLUNK_HOME/var/log/splunk:

splunk_ta_tomcat_main.log
splunk_ta_tomcat_setup.log
splunk_ta_tomcat_util.log

Have you checked this to figure out what is wrong?

https://docs.splunk.com/Documentation/AddOns/released/Tomcat/Troubleshoot

amitm05
Builder

Can you be more precise on data not being in correct format. This will help the community in answering with most relevance.
Have you checked for all the compatibility versions, Splunk, Addon, CIM etc. ?

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...