What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
To monitor Tomcat with JMX, choose the access method that fits where your collector runs: use local JMX on the Tomcat host, remote JMX/RMI for a full JMX client connecting over the network, or Tomcat’s Manager JMXProxyServlet when HTTP requests are enough. For basic status data, Manager’s status endpoint may be simpler. Remote JMX needs fixed ports and strong access controls; the HTTP proxy also grants access to powerful administrative operations.
Choose a monitoring path
Start by deciding whether you need JMX itself, how the collector reaches Tomcat, and whether it only reads data or also manages the server.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Professional Apache Tomcat | $9.46 | Buy on Amazon |
| 2 |
|
Tomcat: The Definitive Guide | $28.00 | Buy on Amazon |
| 3 |
|
Apache Tomcat 7 | $40.00 | Buy on Amazon |
| 4 |
|
Apache Tomcat Bible | $36.14 | Buy on Amazon |
| 5 |
|
Apache Tomcat 11 Cheat Sheet | $3.00 | Buy on Amazon |
| Method | Best suited to | Main consideration |
|---|---|---|
| Local JMX client | A monitoring tool running on the Tomcat host under the same operating-system user | Tomcat’s guide says remote JMX configuration is unnecessary for this local case. Tomcat 10.1 monitoring guide. |
| Remote JMX/RMI | A full JMX-capable client or agent connecting over the network | Configure stable JMX and RMI ports, TLS, authentication, and least-privilege access; allow the required ports through firewalls. Tomcat 10.1 monitoring guide. |
| Manager JMXProxyServlet | Scripts or tools that need selected MBean data over HTTP | It avoids a separate JMX client connection workflow but requires privileged Manager access and can read, set, or invoke MBeans. Tomcat 10.1 monitoring guide; Tomcat 9 Manager guide. |
| Manager status endpoint | Basic JVM and connector status, including data for tooling | Tomcat documents HTML, XML, and JSON status forms, with differing levels of detail. Tomcat 9 Manager guide. |
| Tomcat Ant JMX tasks | Existing Ant automation for querying or managing MBeans | Tasks include reading and querying as well as setting attributes and invoking operations, so separate observation from change permissions. Tomcat 10.1 monitoring guide. |
Compare the options against five practical questions: Is collection local or remote? Does the client support JMX/RMI or only HTTP? Which ports and firewall routes are acceptable? What access boundary can you enforce? Do you need observation alone, or management operations too?
Enable remote JMX/RMI safely
The following configuration concepts are documented for Tomcat 10.1. Confirm the exact Java and Tomcat options for the versions and service setup you run. A stable remote connection requires both the JMX registry port and the RMI port; if the RMI port is unset, the adaptor may choose a random port, making firewall rules difficult to maintain.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- Used Book in Good Condition
- Set fixed ports. Add
com.sun.management.jmxremote.portandcom.sun.management.jmxremote.rmi.portto the JVM options used by Tomcat. Permit those ports only from the monitoring network or hosts that need access. - Configure authentication and roles. Use the documented password and access files, assigning monitoring identities only the permissions required. Do not copy example passwords from documentation.
- Enable TLS. Tomcat’s guide documents JMX SSL and registry SSL options and strongly recommends TLS together with authentication for remote access.
- Protect the password file. Make it read-only and accessible only to the operating-system account running Tomcat.
- Apply options through the correct service mechanism. The guide’s displayed example uses Windows
setenv.batsyntax. On Unix-like systems, remove the leadingset; if Tomcat runs as a Windows service, configure JVM options through that service’s configuration rather than assuming the batch file is used. - Test from the intended collector. Confirm that it can connect through the chosen ports and read the expected MBeans, while an unauthorized host or identity cannot.
The guide also documents JAAS as an alternative login configuration. Use the access-control and TLS settings that match your deployment; the example values in documentation are illustrative, not production credentials. See Tomcat 10.1 Monitoring and Managing Tomcat.
Use Manager’s HTTP interfaces when they fit
JMXProxyServlet for selected MBean operations
Tomcat describes the JMXProxyServlet as allowing a client to issue JMX queries through HTTP. It supports query, get, set, and invoke forms, which makes it useful for a small script that needs a few values without a full Java JMX client. The same capabilities mean it is not a read-only status feed. The Tomcat 9 Manager manual calls the interface a low-level, root-like administrative interface.
Rank #2
Access requires the manager-jmx role. Restrict that role to trusted users and networks, and use the endpoint and query syntax documented for your deployed Tomcat version: the cited paths and forms are from the Tomcat 9 manual and should not be assumed identical in other versions. The Manager guide also warns that its text and JMX interfaces do not have the same CSRF protections as the HTML interface. Avoid sharing a script/JMX identity with routine browser sessions; close authenticated browser sessions after testing.
Status endpoint for basic server health
If you only need a snapshot of JVM memory and connector, thread, or request information, the Manager status interface may be sufficient. Tomcat documents status and status/all forms, with HTML, XML, and JSON variants and differences in detail. Consult the matching version’s Manager documentation before building a collector around a particular path or response format.
Recommended Free Tools
Rank #3
Decide what to collect and how to read it
Useful starting points include JVM memory, connector thread-pool occupancy, request counts and errors, processing time, bytes in and out, and application Manager statistics. Manager status documents JVM memory and connector/thread/request information; JMX can expose additional Tomcat and application-specific attributes. The actual MBean names and available attributes depend on the running server, its version, deployed connectors, applications, and configuration, so inspect the live MBean inventory rather than assuming every server exposes the same set.
- JVM memory: Track consumption over time and relate it to workload and application behavior.
- Connector and thread activity: Observe thread use alongside requests and processing time to understand server activity.
- Request and traffic counters: Collect counts, errors, and bytes in or out; calculate changes between samples when you need a current rate or incident signal.
- Application-specific data: Use application MBeans where available, verifying their names and attributes on the actual runtime.
A cumulative error counter is a snapshot of all errors since its counter began, not evidence by itself that errors are increasing now. Compare repeated samples and use the delta over a known interval when interpreting changes. An Apache presentation from 2016 illustrates this measurement principle with session counts and request errors and describes a custom MBean for application request statistics; treat it as an example of interpreting counters, not current configuration guidance. ApacheCon 2016 presentation on monitoring Tomcat.
Rank #4
Keep monitoring access separate from control
JMX is a management interface as well as a source of measurements. Tomcat’s Ant task examples include opening a connection, querying Catalina:type=Manager,*, reading a Manager MBean attribute, and invoking operations such as listing session IDs. They also include setting attributes and invoking operations, which can change runtime behavior. Give routine collectors read-only access unless a specific operational task justifies broader privileges; keep control workflows and identities separate where possible.
- Do not expose remote JMX without authentication; use TLS with authentication for remote connections.
- Use fixed registry and RMI ports when firewall rules must be predictable.
- Keep password files restricted to the Tomcat operating-system account.
- Treat
manager-jmxas privileged administrative access and constrain both its users and network reachability. - Do not grant write or invoke capability to a collector whose job is only to observe.
For configuration details, consult the version-matched Tomcat monitoring guide and Manager guide.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




