Skip to content

Source types for the Splunk Add-on for Tomcat

The Splunk Add-on for Tomcat supports the following data sources. All access logs that need to be CIM-Compliant should use the tomcat:access:log:splunk sourcetype.

Data source Collection method Source type CIM data models ITSI data modules
Thread information from JMX MBean operations Modular input (dumpAllThreads) tomcat:jmx JVM, Performance Application Server data model objects: Inventory, Performance
Performance metrics from JMX MBean attributes Splunk Add-on for JMX tomcat:jmx JVM, Performance Application Server data model objects: Inventory, Performance
Catalina*.log, localhost*.log, manager*.log, host-manager*.log File monitoring tomcat:runtime:log N/A Application Server data model object: Inventory
localhost_access_log_splunk*.txt File monitoring tomcat:access:log:splunk Web localhost_access_log*.txt
localhost_access_log*.txt File monitoring tomcat:access:log N/A Application Server data model objects: Inventory, Performance

You can view the recommended fields section to collect data using the tomcat:access:log:splunk sourcetype.