Splunk® Supported Add-ons

Splunk Add-on for IBM WebSphere Application Server

Release history for the Splunk Add-on for IBM WebSphere Application Server

Latest version

The latest version of the Splunk Add-on for IBM WebSphere Application Server is version 5.2.0. See Release notes for the Splunk Add-on for IBM WebSphere Application Server for the release notes of this latest version.


Version 5.1.0

About this release

Version 5.1.0 of the Splunk Add-on for IBM WebSphere Application Server is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 8.1.x, 8.2.x, 9.0.x
CIM 5.0.1
Platforms Platform independent
Vendor Products IBM WebSphere Application Server versions 8.5.x, 9.0.0, 9.0.5.6, 9.0.5.8, and 9.0.5.12

The field alias functionality is compatible with the current version of this add-on. The current version of this add-on does not support older field alias configurations.

For more information about the field alias configuration change, refer to the Splunk Enterprise Release Notes.

New features

Version 5.1.0 of the Splunk Add-on for IBM WebSphere Application Server has the following new features.

  • Support for IBM Websphere version 9.0.5.12
  • Compatibility with CIM version 5.0.1
  • Corrected the input for the ibm:was:profileCreationLog sourcetype to monitor only the expected files.


Fixed issues

Version 5.1.0 of the Splunk Add-on for IBM WebSphere Application Server has the following fixed issues.


Known issues

Version 5.1.0 of the Splunk Add-on for IBM WebSphere Application Server has the following known issues.


Date filed Issue number Description
2022-09-27 ADDON-56098, ADDON-55876, ADDON-56099 First and Last events are containing garbage values. Events are not breaking properly.
2022-09-27 ADDON-56105, ADDON-56100 Unwanted events are getting ingested in serverExceptionLog sourcetype.

Third-party software attributions

Some of the components included in this add-on are licensed under free or open source licenses. We wish to thank the contributors to those projects.

A complete listing of third-party software information for this add-on is available as a text file for download:
Splunk Add-on for IBM WAS third-party software credits.


Version 5.0.0

Version 5.0.0 of the Splunk Add-on for IBM WebSphere Application Server was released on September 24, 2021

About this release

Version 5.0.0 of the Splunk Add-on for IBM WebSphere Application Server is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 8.0.x, 8.1.x, 8.2.x
CIM 4.20.0
Platforms Platform independent
Vendor Products IBM WebSphere Application Server versions 8.5.x, 9.0.0, 9.0.5.6 and 9.0.5.8

The field alias functionality is compatible with the current version of this add-on. The current version of this add-on does not support older field alias configurations.

For more information about the field alias configuration change, refer to the Splunk Enterprise Release Notes.

New features

Version 5.0.0 of the Splunk Add-on for IBM WebSphere Application Server has the following new features.

  • Support for IBM Websphere 9.0.5.6 and 9.0.5.8
  • Support for Splunk Universal Forwarder
  • Provides static file monitoring stanzas for each sourcetype by default
  • Removed programmatic creation of file monitoring stanzas. The stanzas will now need to be set manually in inputs.conf. The default inputs.conf has some default stanzas for each sourcetype that can be used.
  • Removed user interface - you can only use configurations with a deployment server or backend changes.
  • Multiple Server Support
  • CIM mapping and enhancements
    • ibm:was:gcLog sourcetype is now mapped to Performance.Memory data model instead of Compute_Inventory.All_Inventory
    • ibm:was:httpLog sourcetype is now mapped to Web:Web instead of Performance.All_Performance
    • Removed data model mapping from ibm:was:serverIndex sourcetype.
    • Threadpool MBean events are mapped to the JVM.Threading data model.
    • Added support for CIM v4.20.0
  • Migrated ibm_was_inventory CSV lookup to KV Store lookup
  • Removed Python2 support. This add-on only supports python3 for future releases.
  • Removed support for Splunk 7.x.
  • Removed prebuilt panels shipped with the add-on.


Fixed issues

Version 5.0.0 of the Splunk Add-on for IBM WebSphere Application Server has the following fixed issues.


Date resolved Issue number Description
2021-08-10 ADDON-16900 Configuration page displays Read Operation Timed Out error while saving.
2021-08-10 ADDON-24810 Addon requires restart to collect data for first time after installation

Known issues

Version 5.0.0 of the Splunk Add-on for IBM WebSphere Application Server has the following known issues.


Date filed Issue number Description
2022-09-27 ADDON-56098, ADDON-55876, ADDON-56099 First and Last events are containing garbage values. Events are not breaking properly.
2022-09-27 ADDON-56105, ADDON-56100 Unwanted events are getting ingested in serverExceptionLog sourcetype.

Third-party software attributions

Some of the components included in this add-on are licensed under free or open source licenses. We wish to thank the contributors to those projects.

A complete listing of third-party software information for this add-on is available as a PDF file for download:
Splunk Add-on for IBM WAS third-party software credits.


Version 4.0.1

Version 4.0.1 of the Splunk Add-on for IBM WebSphere Application Server is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 7.0.x, 7.1.x, 7.2.x, 7.3.x, 8.0.x
CIM 4.14 and above
Platforms Platform independent
Vendor Products IBM WebSphere Application Server versions 8.5.5 - 9.0.0

The field alias functionality is compatible with the current version of this add-on. The current version of this add-on does not support older field alias configurations.

For more information about the field alias configuration change, refer to the Splunk Enterprise Release Notes.

New features

Version 4.0.1 of the Splunk Add-on for IBM WebSphere Application Server has the following new features.

  • Default support for Python3

Fixed issues

Version 4.0.1 of the Splunk Add-on for IBM WebSphere Application Server has the following fixed issues.


Date resolved Issue number Description
2020-01-19 ADDON-23337 Splunk Add-on for IBM WebSphere Application Server 3.1.0 sourcetype not supported

Known issues

Version 4.0.1 of the Splunk Add-on for IBM WebSphere Application Server has the following known issues.


Date filed Issue number Description
2020-01-09 ADDON-24810 Addon requires restart to collect data for first time after installation
2018-01-30 ADDON-16900 Configuration page displays Read Operation Timed Out error while saving.

Third-party software attributions

Version 4.0.1 of the Splunk Add-on for IBM WebSphere Application Server incorporates the following third-party software or libraries.


Version 4.0.0

Version 4.0.0 of the Splunk Add-on for IBM WebSphere Application Server is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 7.0.x, 7.1.x, 7.2.x, 7.3.x, 8.0.x
CIM 4.14 and above
Platforms Platform independent
Vendor Products IBM WebSphere Application Server versions 8.5.5 - 9.0.0

New features

Version 4.0.0 of the Splunk Add-on for IBM WebSphere Application Server has the following new features.

  • Support for Python3

Fixed issues

Version 4.0.0 of the Splunk Add-on for IBM WebSphere Application Server has the following fixed issues.


Date resolved Issue number Description
2020-01-19 ADDON-23337 Splunk Add-on for IBM WebSphere Application Server 3.1.0 sourcetype not supported

Known issues

Version 4.0.0 of the Splunk Add-on for IBM WebSphere Application Server has the following known issues.

Date filed Issue number Description
2020-01-09 ADDON-24810 Addon requires restart to collect data for first time after installation
2018-01-30 ADDON-16900 Configuration page displays Read Operation Timed Out error while saving.

Third-party software attributions

Version 4.0.0 of the Splunk Add-on for IBM WebSphere Application Server incorporates the following third-party software or libraries.

Version 3.1.0

Version 3.1.0 of the Splunk Add-on for IBM WebSphere Application Server is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 6.0 and above
CIM 4.2 and above
Platforms Platform independent
Vendor Products IBM WebSphere Application Server versions 7.0.0 - 8.5.5

Migration Guide

The Splunk Add-on for IBM WebSphere Application server replaces the Splunk App for WebSphere Application Server in its entirety. There is no backwards compatibility between this add-on and the old app and its two add-ons. If you have the old app and add-ons installed, uninstall or disable them and begin collecting new and historical data with this new add-on instead.

Upgrade Guide

The line breaker rule for the http_access.log and http_error.log logs has changed in the Splunk Add-on for IBM WebSphere Application Server version 3.1.0. If you had enabled http access logging and http error logging in IBM WebSphere and collected http_access.log and http_error.log using the Splunk Add-on for IBM WebSphere Application Server 3.0.0, you will need to fix the line breaks in the older data after upgrading to the Splunk Add-on for IBM WebSphere Application Server 3.1.0.

New features

Version 3.1.0 of the Splunk Add-on for IBM WebSphere Application Server has the following new features.

Date Issue number Description
2015-10-19 ADDON-6104 Modifications to support integration with ITSI including two new data sources: gc.log and serverindex.xml. These new sources are mapped to the Application Server and OS ITSI data models. Other sources are also mapped to the Application Server and OS ITSI data models. In addition, some sources are mapped to the Inventory and Performance CIM data models. See the source types table for more information.
2016-03-16 ADDON-8323 Add saved search Server Index - WAS Inventory Lookup to generate a lookup file that is used to correlate data from multiple logs and populate certain fields in the events.

Fixed issues

Version 3.1.0 of the Splunk Add-on for IBM WebSphere Application Server has the following fixed issues.

Date Issue number Description
2016-02-27 ADDON-7977 tag=performance should contain response_code field.
2016-02-27 ADDON-7980 ip_address field is not extracted.
2015-09-14 ADDON-6384 If Splunk Add-on for JMX version 3.1.0 or later is used with the Splunk Add-on for IBM WebSphere Application Server version 3.0.0 or later, the source type override in the Splunk Add-on for IBM WebSphere Application Server incorrectly assigns the source type as jmx instead of ibm:was:jmx. Workaround: specify a source type of ibm:was:jmx in the JMX input.
2015-06-10 ADDON-4216 Data inputs page appears to allow you to configure new inputs, but its only purpose is to allow you to easily enable the HPEL data collection input, which requires no additional configuration in this page.

Known issues

Version 3.1.0 of the Splunk Add-on for IBM WebSphere Application Server has the following known issues.

Date Defect number Description
2016-01-13 ADDON-5325 requireClientCert=true in server.conf is not supported by add-ons using modular inputs and REST. If this setting is enabled in server.conf, communication is broken between the modular input and splunkd and the add-on stops collecting data. The following error appears in the splunkd.log: "SSL3_GET_CLIENT_CERTIFICATE:peer did not return a certificate." The workaround is to set requireClientCert=false.
2015-06-29 ADDON-4360 The "HPEL logs start date" field in the setup page or the start_date argument in ibm_was.conf can only be configured before you enable the input for the first time.
2015-06-23 ADDON-4321/ ADDON-4204 Some files collected via the monitor input have invalid source type names such as responseFile-too_small.
2015-06-10 ADDON-4218 Any messages shown on the setup page after saving continue to show until you click on save again.
2015-06-09 ADDON-4206 JMX input throws errors "ERROR - Error executing JMX stanza..." because the Splunk Add-on for JMX queries attributes that the WAS MBean does not implement. Can be safely ignored.

Third-party software attributions

Version 3.1.0 of the Splunk Add-on for IBM WebSphere Application Server incorporates the following third-party software or libraries.


Version 3.0.0

Version 3.0.0 of the Splunk Add-on for IBM WebSphere Application Server has the same compatibility specifications as version 3.1.0.

Migration Guide

The Splunk Add-on for IBM WebSphere Application server replaces the Splunk App for WebSphere Application Server in its entirety. There is no backwards compatibility between this add-on and the old app and its two add-ons. If you have the old app and add-ons installed, uninstall or disable them and begin collecting new and historical data with this new add-on instead.

New features

Version 3.0.0 of the Splunk Add-on for IBM WebSphere Application Server has the following new features.

Date Issue number Description
07/01/15 ADDON-1324 New Splunk-supported add-on that replaces the Splunk App for WebSphere Application Server and brings it up to date through version 8.5.5, including support for High Performance Extensible Logging (HPEL) in WAS 8.x.

Known issues

Version 3.0.0 of the Splunk Add-on for IBM WebSphere Application Server has the following known issues.

Date Defect number Description
2016-01-13 ADDON-5325 requireClientCert=true in server.conf is not supported by add-ons using modular inputs and REST. If this setting is enabled in server.conf, communication is broken between the modular input and splunkd and the add-on stops collecting data. The following error appears in the splunkd.log: "SSL3_GET_CLIENT_CERTIFICATE:peer did not return a certificate." The workaround is to set requireClientCert=false.
09/14/15 ADDON-5524/ ADDON-6384 If version 3.1.0 of the Splunk Add-on for JMX is used with the Splunk Add-on for IBM WebSphere Application Server version 3.0.0, the source type override in the Splunk Add-on for IBM WebSphere Application Server incorrectly assigns the source type as jmx instead of ibm:was:jmx. Workaround: specify a source type of ibm:was:jmx in the JMX input.
06/29/15 ADDON-4360 The "HPEL logs start date" field in the setup page or the start_date argument in ibm_was.conf can only be configured before you enable the input for the first time.
06/23/15 ADDON-4321/ ADDON-4204 Some files collected via the monitor input have invalid source type names such as responseFile-too_small.
06/10/15 ADDON-4218 Any messages shown on the setup page after saving continue to show until you click on save again.
06/10/15 ADDON-4216 Data inputs page appears to allow you to configure new inputs, but its only purpose is to allow you to easily enable the HPEL data collection input, which requires no additional configuration in this page.
06/09/15 ADDON-4206 JMX input throws errors "ERROR - Error executing JMX stanza..." because the Splunk Add-on for JMX queries attributes that the WAS MBean does not implement. Can be safely ignored.

Third-party software attributions

Version 3.0.0 of the Splunk Add-on for IBM WebSphere Application Server incorporates the following third-party software or libraries.

Last modified on 16 September, 2024
Release notes for the Splunk Add-on for IBM WebSphere Application Server   Source types for the Splunk Add-on for IBM WebSphere Application Server

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters