{"id":36703541,"url":"https://github.com/nlighten/tomcat_exporter","last_synced_at":"2026-01-12T11:40:30.605Z","repository":{"id":39617152,"uuid":"83144308","full_name":"nlighten/tomcat_exporter","owner":"nlighten","description":"A Prometheus exporter for Apache Tomcat","archived":false,"fork":false,"pushed_at":"2023-07-21T06:04:54.000Z","size":115,"stargazers_count":142,"open_issues_count":5,"forks_count":63,"subscribers_count":8,"default_branch":"master","last_synced_at":"2025-07-03T23:45:06.694Z","etag":null,"topics":["metrics","prometheus","prometheus-exporter","tomcat"],"latest_commit_sha":null,"homepage":"","language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/nlighten.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null}},"created_at":"2017-02-25T16:15:56.000Z","updated_at":"2025-05-21T06:38:24.000Z","dependencies_parsed_at":"2022-09-15T21:42:13.832Z","dependency_job_id":null,"html_url":"https://github.com/nlighten/tomcat_exporter","commit_stats":{"total_commits":82,"total_committers":9,"mean_commits":9.11111111111111,"dds":"0.18292682926829273","last_synced_commit":"bc6a2d257a94b3603249e14b8bdb06e0e555f8be"},"previous_names":[],"tags_count":17,"template":false,"template_full_name":null,"purl":"pkg:github/nlighten/tomcat_exporter","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nlighten%2Ftomcat_exporter","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nlighten%2Ftomcat_exporter/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nlighten%2Ftomcat_exporter/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nlighten%2Ftomcat_exporter/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/nlighten","download_url":"https://codeload.github.com/nlighten/tomcat_exporter/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nlighten%2Ftomcat_exporter/sbom","scorecard":{"id":690631,"data":{"date":"2025-08-11","repo":{"name":"github.com/nlighten/tomcat_exporter","commit":"bc6a2d257a94b3603249e14b8bdb06e0e555f8be"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":1.7,"checks":[{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Code-Review","score":1,"reason":"Found 3/28 approved changesets -- score normalized to 1","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: containerImage not pinned by hash: Dockerfile:1: pin your Docker image by updating tomcat:9.0-jdk17-openjdk-slim to tomcat:9.0-jdk17-openjdk-slim@sha256:a7ce420543bb7fb3f31e2580063be9c8b99882b980663cf3246d8fb33cdd557c","Info:   0 out of   1 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 5 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":0,"reason":"25 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-23hv-mwm6-g8jf","Warn: Project is vulnerable to: GHSA-2c9m-w27f-53rm","Warn: Project is vulnerable to: GHSA-5j33-cvvr-w245","Warn: Project is vulnerable to: GHSA-653p-vg55-5652","Warn: Project is vulnerable to: GHSA-83qj-6fr2-vhqg","Warn: Project is vulnerable to: GHSA-fccv-jmmp-qg76","Warn: Project is vulnerable to: GHSA-h2fw-rfh5-95r3","Warn: Project is vulnerable to: GHSA-h3gc-qfqq-6h8f","Warn: Project is vulnerable to: GHSA-wc4r-xq3c-5cf3","Warn: Project is vulnerable to: GHSA-wr62-c79q-cv37","Warn: Project is vulnerable to: GHSA-xcpr-7mr4-h4xq","Warn: Project is vulnerable to: GHSA-25xr-qj8w-c4vf","Warn: Project is vulnerable to: GHSA-7w75-32cg-r6g2","Warn: Project is vulnerable to: GHSA-gqp3-2cvr-x8m3","Warn: Project is vulnerable to: GHSA-hfrx-6qgj-fp6c","Warn: Project is vulnerable to: GHSA-p22x-g9px-3945","Warn: Project is vulnerable to: GHSA-qppj-fm5r-hxr3","Warn: Project is vulnerable to: GHSA-wm9w-rjj3-j356","Warn: Project is vulnerable to: GHSA-4j3c-42xv-3f84","Warn: Project is vulnerable to: GHSA-7jqf-v358-p8g7","Warn: Project is vulnerable to: GHSA-rq2w-37h9-vg94","Warn: Project is vulnerable to: GHSA-344f-f5vg-2jfj","Warn: Project is vulnerable to: GHSA-f268-65qc-98vg","Warn: Project is vulnerable to: GHSA-f4qf-m5gf-8jm8","Warn: Project is vulnerable to: GHSA-vvw4-rfwf-p6hx"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-22T02:13:40.183Z","repository_id":39617152,"created_at":"2025-08-22T02:13:40.183Z","updated_at":"2025-08-22T02:13:40.183Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28338972,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-12T10:58:46.209Z","status":"ssl_error","status_checked_at":"2026-01-12T10:58:42.742Z","response_time":98,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["metrics","prometheus","prometheus-exporter","tomcat"],"created_at":"2026-01-12T11:40:30.064Z","updated_at":"2026-01-12T11:40:30.600Z","avatar_url":"https://github.com/nlighten.png","language":"Java","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003e NOTE: The official Prometheus [java client](https://github.com/prometheus/client_java) now supports some overlapping functionality like the [servlet filter](https://github.com/prometheus/client_java#servlet-filter). I suggest users to seriously consider to switch as you can expect more long term support from that implementation. I am considering sunsetting support for this exporter by the end of 2022.\n\n\n# Prometheus Tomcat Exporter\nA set of collectors that can be used to monitor Apache Tomcat instances.\n\n\n### Available metrics\nThe following Tomcat related metrics are provided:\n\n* Thread pool metrics\n* Session metrics\n* Request processor metrics\n* Database connection pool metrics\n* Tomcat version info\n* Servlet response time metrics \n* Database response time metrics\n\n### Using this library\nIf you are running Tomcat in the conventional non-embedded setup we recommended to add the following jars (see `pom.xml` for the correct versions) to the `$CATALINA_BASE/lib` directory or another directory on the Tomcat `common.loader` path.\nUsing the `common.loader` is important as we need to make sure that all metrics are registered using the same class loader.\n\n* [simpleclient](https://search.maven.org/#search%7Cga%7C1%7Ca%3A%22simpleclient%22)\n* [simpleclient_common](https://search.maven.org/#search%7Cga%7C1%7Ca%3A%22simpleclient_common%22)\n* [simpleclient_servlet](https://search.maven.org/#search%7Cga%7C1%7Ca%3A%22simpleclient_servlet%22)\n* [simpleclient_servlet_common](https://search.maven.org/#search%7Cga%7C1%7Ca%3A%22simpleclient_servlet_common%22)\n* [simpleclient_hotspot](https://search.maven.org/#search%7Cga%7C1%7Ca%3A%22simpleclient_hotspot%22)\n* [tomcat_exporter_client](https://search.maven.org/#search%7Cga%7C1%7Ca%3A%22tomcat_exporter_client%22)\n\nNext, rename [tomcat_exporter_servlet](https://search.maven.org/#search%7Cga%7C1%7Ca%3A%22tomcat_exporter_servlet%22) war file to `metrics.war` and add it to the webapps directory of Tomcat. After restart of tomcat you should be able to access metrics via the `/metrics/` endpoint.   \n\n### Example Dockerfile \nThe following Dockerfile provides an example how you include the exporter in a Tomcat image:\n\n\n```\nFROM tomcat:9.0-jdk17-openjdk-slim\n\nENV TOMCAT_SIMPLECLIENT_VERSION=0.12.0\nENV TOMCAT_EXPORTER_VERSION=0.0.15\n\nRUN apt-get update \u0026\u0026 apt-get install -y curl \u0026\u0026 \\\n    curl -v --fail --location https://search.maven.org/remotecontent?filepath=io/prometheus/simpleclient/${TOMCAT_SIMPLECLIENT_VERSION}/simpleclient-${TOMCAT_SIMPLECLIENT_VERSION}.jar --output /usr/local/tomcat/lib/simpleclient-${TOMCAT_SIMPLECLIENT_VERSION}.jar \u0026\u0026 \\\n    curl -v --fail --location https://search.maven.org/remotecontent?filepath=io/prometheus/simpleclient_common/${TOMCAT_SIMPLECLIENT_VERSION}/simpleclient_common-${TOMCAT_SIMPLECLIENT_VERSION}.jar --output /usr/local/tomcat/lib/simpleclient_common-${TOMCAT_SIMPLECLIENT_VERSION}.jar \u0026\u0026 \\\n    curl -v --fail --location https://search.maven.org/remotecontent?filepath=io/prometheus/simpleclient_hotspot/${TOMCAT_SIMPLECLIENT_VERSION}/simpleclient_hotspot-${TOMCAT_SIMPLECLIENT_VERSION}.jar --output /usr/local/tomcat/lib/simpleclient_hotspot-${TOMCAT_SIMPLECLIENT_VERSION}.jar \u0026\u0026 \\\n    curl -v --fail --location https://search.maven.org/remotecontent?filepath=io/prometheus/simpleclient_servlet/${TOMCAT_SIMPLECLIENT_VERSION}/simpleclient_servlet-${TOMCAT_SIMPLECLIENT_VERSION}.jar --output /usr/local/tomcat/lib/simpleclient_servlet-${TOMCAT_SIMPLECLIENT_VERSION}.jar \u0026\u0026 \\\n    curl -v --fail --location https://search.maven.org/remotecontent?filepath=io/prometheus/simpleclient_servlet_common/${TOMCAT_SIMPLECLIENT_VERSION}/simpleclient_servlet_common-${TOMCAT_SIMPLECLIENT_VERSION}.jar --output /usr/local/tomcat/lib/simpleclient_servlet_common-${TOMCAT_SIMPLECLIENT_VERSION}.jar \u0026\u0026 \\\n    curl -v --fail --location https://search.maven.org/remotecontent?filepath=nl/nlighten/tomcat_exporter_client/${TOMCAT_EXPORTER_VERSION}/tomcat_exporter_client-${TOMCAT_EXPORTER_VERSION}.jar --output /usr/local/tomcat/lib/tomcat_exporter_client-${TOMCAT_EXPORTER_VERSION}.jar \u0026\u0026 \\\n    curl -v --fail --location https://search.maven.org/remotecontent?filepath=nl/nlighten/tomcat_exporter_servlet/${TOMCAT_EXPORTER_VERSION}/tomcat_exporter_servlet-${TOMCAT_EXPORTER_VERSION}.war --output /usr/local/tomcat/webapps/metrics.war\n``` \n\n### Servlet response time metrics\nIf you want servlet response time metrics you can configure the `TomcatServletMetricsFilter` by adding it to the $CATALINA_BASE/conf/web.xml as shown below. There is no need to modify already deployed applications.\n\n```xml\n\u003cfilter\u003e\n  \u003cfilter-name\u003eServletMetricsFilter\u003c/filter-name\u003e\n  \u003cfilter-class\u003enl.nlighten.prometheus.tomcat.TomcatServletMetricsFilter\u003c/filter-class\u003e\n  \u003casync-supported\u003etrue\u003c/async-supported\u003e\n  \u003cinit-param\u003e\n    \u003cparam-name\u003ebuckets\u003c/param-name\u003e\n    \u003cparam-value\u003e.01, .05, .1, .25, .5, 1, 2.5, 5, 10, 30\u003c/param-value\u003e\n  \u003c/init-param\u003e\n\u003c/filter\u003e\n\n\u003cfilter-mapping\u003e\n  \u003cfilter-name\u003eServletMetricsFilter\u003c/filter-name\u003e\n  \u003curl-pattern\u003e/*\u003c/url-pattern\u003e\n\u003c/filter-mapping\u003e\n```\nFor an explanation on histograms and buckets please see the [prometheus documentation](https://prometheus.io/docs/concepts/metric_types/#histogram).\n\n### Database response time metrics\nDatabase response time metrics are only available when using the [Tomcat JDBC Pool](http://tomcat.apache.org/tomcat-8.5-doc/jdbc-pool.html) as this collector uses an interceptor mechanism that is only available for this type of pool.\n\nThe interceptor will collect the following metrics:\n\n* A histogram with global query response times\n* A histogram with per query response times for slow queries (optional)\n* A gauge with per query error counts (optional) \n\nConfiguration is usually done in Tomcat's `server.xml` or `context.xml`\n\n```xml\n\u003cResource name=\"jdbc/TestDB\"\n           auth=\"Container\"\n           type=\"javax.sql.DataSource\"\n           factory=\"org.apache.tomcat.jdbc.pool.DataSourceFactory\"\n           jdbcInterceptors=\"nl.nlighten.prometheus.tomcat.TomcatJdbcInterceptor(logFailed=true,logSlow=true,threshold=1000,buckets=.01|.05|.1|1|10,slowQueryBuckets=1|10|30)\"\n           username=\"root\"\n           password=\"password\"\n           driverClassName=\"com.mysql.jdbc.Driver\"\n           url=\"jdbc:mysql://localhost:3306/mysql\"/\u003e\n```\n\nConfiguration options of the interceptor are as shown above and have the following meaning:\n- logFailed: if set to 'true' collect metrics on failed queries\n- logSlow: if set to 'true' collect metrics on metrics exceeding threshold\n- threshold: the threshold in ms above which metrics will be collected if logSlow=true\n- buckets: the buckets separated by a pipe (\"|\") symbol to be used for the global query response times, defaults to .01|.05|.1|.25|.5|1|2.5|10\n- slowQueryBuckets: the buckets separated by a pipe (\"|\") symbol to be used for the global query response times, defaults to 1|2.5|10|30\n\n\u003e NOTE: \n\u003e- Enabling logFailed and logSlow may lead to a lot of additional metrics., so be careful !!!  \n\u003e- If you are defining your data source on application level (so inside your war), you need to set [bindOnInit](https://tomcat.apache.org/tomcat-9.0-doc/config/http.html#Standard_Implementation) to ensure that your data source has been initialized before the metrics application starts. \n\n### Embedded mode\nIf you run Tomcat in embedded mode, please look at the `AbstractTomcatMetricsTest` for an example on how to configure the various exporters when running embedded.\n\n### Javadocs\nThere are canonical examples defined in the class definition Javadoc of the client packages.\n\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fnlighten%2Ftomcat_exporter","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fnlighten%2Ftomcat_exporter","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fnlighten%2Ftomcat_exporter/lists"}