Source types for the Splunk Add-on for Tomcat¶
The Splunk Add-on for Tomcat supports the following data sources. All access logs that need to be CIM-Compliant should use the tomcat:access:log:splunk sourcetype.
| Data source | Collection method | Source type | CIM data models | ITSI data modules |
|---|---|---|---|---|
| Thread information from JMX MBean operations | Modular input (dumpAllThreads) | tomcat:jmx |
JVM, Performance | Application Server data model objects: Inventory, Performance |
| Performance metrics from JMX MBean attributes | Splunk Add-on for JMX | tomcat:jmx |
JVM, Performance | Application Server data model objects: Inventory, Performance |
| Catalina*.log, localhost*.log, manager*.log, host-manager*.log | File monitoring | tomcat:runtime:log |
N/A | Application Server data model object: Inventory |
| localhost_access_log_splunk*.txt | File monitoring | tomcat:access:log:splunk |
Web | localhost_access_log*.txt |
| localhost_access_log*.txt | File monitoring | tomcat:access:log |
N/A | Application Server data model objects: Inventory, Performance |
You can view the recommended fields section to collect data using the tomcat:access:log:splunk sourcetype.