All Apps and Add-ons

Splunk-Add on for Tomcat - Totally lost on what I am doing.

mc210274
New Member

Hello,

I am totally new to Splunk so please be patient with me.

I installed Splunk 8.0.0 on a Windows Server 2016 machine and I am able to pull in Windows Event Logs and search them without an issue. However, besides the Windows Event Logs we also have several machines running Tomcat and we want to pull in the Tomcat Logs as well. So I installed the Splunk-Add on for Tomcat 2.0 and this is where all the trouble starts. And yes I read through the whole Splunk-Add for Tomcat documentation but it does not really make sense to me.

So installed the Splunk-Add on for Tomcat and I first went to Applications --> Set-up for the Add-on. The settings on here already do not make any sense to me. I have about 10 servers running tomcat. If I set a specific host name in the JMX path how am I going to add the additional 9 Tomcat servers? See screenshot below:
alt text

After that I went into Settings --> Data Input --> Splunk Add-On for Tomcat --> + Add New but alll I get in there is this:

alt text

When I click on Next the then I get the error message
------------ Encountered the following error while trying to save: setEntity - tried to commit empty entity----------------------------

As I stated before I read through the Splunk documentation and tried to figure out what I need to do to add at least one of my test Tomcat Servers to the add on but I just dont get it. Can someone please point me into the right direction.

Thank you

Tags (1)
0 Karma
1 Solution

anantcd
Explorer

As per your requirement (which involves ingesting data from multiple Tomcat Servers using JMX), I would recommend using Splunk Add-on for Java Management Extensions (JMX) to ingest data.
You can find more details about app configuration here.

View solution in original post

0 Karma

anantcd
Explorer

As per your requirement (which involves ingesting data from multiple Tomcat Servers using JMX), I would recommend using Splunk Add-on for Java Management Extensions (JMX) to ingest data.
You can find more details about app configuration here.

0 Karma

anantcd
Explorer

Not sure why links are not working. Reposting the links in comments:
Splunkbase: https://splunkbase.splunk.com/app/2647/#/overview
Docs: https://docs.splunk.com/Documentation/AddOns/released/JMX/Configureinput

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...