Splunk® IT Service Intelligence

Modules

Download manual as PDF

Download topic as PDF

Application Server Module configurations

Follow the below steps to configure your ITSI deployment to receive application server data.

Module entity roles

See the below table to identify the roles that the Application Server Module assigns to entities:

ITSI Module ITSI Role
ITSI Application Server Module application_server

Step 1: Install supported technologies

See About installing Splunk add-ons to learn how to install a Splunk add-on in the following deployment scenarios.

Install your ITSI supported technologies onto your deployment using the reference table below. For single instance deployments, install supported technologies onto your single instance.

Technology Name Installation link Search Heads Indexers Heavy Forwarders
Splunk Add-on for Tomcat Installation guide x x x
Splunk Add-on for IBM WebSphere Application Server Installation guide x x x

Configure the Splunk Add-on for IBM WebSphere Application Server to send WebSphere Applications Server data to your Splunk platform deployment. See the Splunk Add-on for IBM WebSphere Application Server configuration section for more information.

Configure the Splunk Add-on for Tomcat to collect and send local and remote Tomcat server data to your Splunk platform deployment. See the Splunk Add-on for Tomcat configuration section for more information.

Step 2: Install and configure the Splunk Add-on for Java Management Extensions (JMX) to collect and send data to your Splunk platform

Java Management Extension environments

The Application Server Module uses the Splunk Add-on for Java Management Extensions (JMX) to poll local or remote JMX Management Servers running in Java Virtual Machines and index MBean attributes, outputs from MBean operations, and MBean notifications.

Install the JMX add-on on the servers where your data is ingested. See the deployment tables below for add-on deployment information. See the Splunk Add-on for Java Management Extensions (JMX) installation and configuration documentation guides for more information.

Step 3: Build necessary lookups for correlating data

In order to correlate data between app server logs and JMX metrics, lookups are required. The process for configuring lookups for both Tomcat and Websphere Add-ons are below.

Enable Tomcat searches for building lookups

See the Splunk Add-on for Tomcat documentation for data collection enablement. The saved searches required to build the necessary lookups are disabled by default. To enable them go to Settings > Searches, Reports and Alerts and select Splunk Add-on for Tomcat for the App Context. These searches will run every 4 hours. To retrieve results immediately, manually run the following saved searches:

  1. Tomcat version number
  2. Tomcat application server

Tomcatlookups.png


Enable Websphere searches for building lookups

See the Splunk Add-on for IBM WebSphere Application Server documentation for data collection enablement. The saved searches required to build the necessary lookups are disabled by default, to enable them go to Settings > Searches, Reports and Alerts and select Splunk Add-on for IBM WebSphere for the App Context. These searches will run every 4 hours, to retrieve results immediately manually run the following search:

"Server Index - WAS Inventory Lookup"

Webspherelookup.png

Step 4: Enable entity discovery

Enable entity discovery for the module to automatically discover entities for which relevant data has been collected. See Enable the automatic entity discovery search.

Last modified on 20 March, 2020
PREVIOUS
About the Application Server Module
  NEXT
Application Server Module KPIs and thresholds

This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.1.0, 4.1.1, 4.1.2, 4.1.5, 4.2.0, 4.2.1, 4.2.2, 4.2.3, 4.3.0, 4.3.1, 4.4.0, 4.4.1, 4.4.2, 4.4.3


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters