Java error tracking

Know when your Java app breaks, before your users do

ForgeOps connects the errors your Java app reports to the deploys, traces, and changes around them, so when production breaks, the incident already says who's affected, what changed, and where to look.

Servlet 5+ and Spring MVC/Boot integrations report every unhandled request exception automatically. Running on ForgeOps' own dedicated infrastructure, so nothing about a Java app's errors or its users' data gets routed through a third-party error-tracking vendor. See an incident investigated →

Install

<dependency>
  <groupId>io.github.luke-popwell</groupId>
  <artifactId>tracker</artifactId>
  <version>0.13.0</version>
</dependency>

import io.github.lukepopwell.tracker.ForgeOpsTracker;

ForgeOpsTracker.init(config ->
  config.setDsn("https://<api_key>@getforgeops.net/api/v1/events"));

Servlet 5+ and Spring MVC/Boot integrations report every unhandled request exception automatically.

Every client reports the same shape

Wherever it comes from, an event arrives with an exception class, a message, and a backtrace, plus whatever environment/release/server context that client can gather on its own. ForgeOps fingerprints and groups on the first three, so a Java app's issues list works exactly the same way every other language's does: report the same bug a thousand times and it's still one row, not a thousand.

No agent, no sidecar: it's a plain HTTPS POST to ForgeOps' own ingestion API, so nothing about a Java app's traffic gets routed through a third-party pipeline first.


Works with your framework


The Java client hooks in at the framework level, not by wrapping individual calls, so nothing about how you already write Java code has to change.


Servlet 5+

A javax.servlet.Filter catches anything that escapes your own handlers, container-agnostic.

Spring MVC / Boot

A @ControllerAdvice bean reports before Spring's own error page renders.

Plain JVM apps

Set an uncaught exception handler on your own threads for anything outside a servlet container. Errors reported just before a program exits are sent by a shutdown hook (waiting at most 5 seconds); call ForgeOpsTracker.flush() before Runtime.halt.

What it looks like

The issue list

Every Java issue reported into a project shows up here: title, status, assignee, event count, and when it was last seen, the same columns as any other language's project.

The issue list for a project reporting from a Java app

The issue detail

Every occurrence keeps its own timestamp, environment, release, and server, plus the backtrace exactly as Java reported it, expandable per occurrence rather than flattened into one generic stack.

A Java issue's page in ForgeOps: its title, the exception class and the code it came from beneath it, then its verdict with its failure count, customers affected, and when it was first seen, above the triage buttons

Alerting

A new Java issue, a regression, or a spike past a threshold you set can reach Slack, Microsoft Teams, email, PagerDuty, Opsgenie, or a generic webhook, configured per project, per trigger.

Notification rules configured per trigger and channel, e.g. a new issue to Slack, a regression to email

Heartbeats

For the failure mode error tracking can't see on its own: a Java cron job or recurring task that's supposed to run but silently stopped. Each heartbeat gets its own ping URL and its own grace period before it alerts.

A heartbeat's ping URL and status, showing its expected interval, grace period, and last check-in

Background jobs

init() also installs a JVM-wide uncaught-exception handler by default, covering any thread that dies from an exception nobody caught.

A ForgeOps issue for a failing Spring @Async/@Scheduled method: its title, the exception class and the code it came from beneath it, then its verdict with its failure count, customers affected, and when it was first seen, above the triage buttons

Spring's own @Async/@Scheduled methods never let that happen though: Spring routes their exceptions through its own handler/logging instead of ever letting the thread actually die that way. An AsyncUncaughtExceptionHandler needs wiring instead:

@Configuration
public class AsyncErrors
    implements AsyncConfigurer {

  public AsyncUncaughtExceptionHandler
      getAsyncUncaughtExceptionHandler() {
    return (ex, m, p) -> ForgeOpsTracker
        .captureException(ex, Map.of(
            "method", m.getName()));
  }
}

Release health

Once your app is reporting into ForgeOps, every request through the servlet integration also counts as a session: crash-free unless an unhandled exception (or a 5xx response) actually affects it. That gives each release's row on a project's Releases page a real crash-free rate, not just an event count. On by default; counted in-process and flushed as one small aggregate report every 60 seconds, not one network call per request. Requires a plan that includes release health; on a plan that doesn't, the periodic reports are accepted but not recorded (the response says why), so a working setup never looks broken.

A project's Releases page, showing each release's crash-free rate and session count next to its issue and event totals
ForgeOpsTracker.init(config -> {
  config.setTrackSessions(false); // opt out entirely
  config.setSessionFlushInterval(
      Duration.ofSeconds(30)); // default 60
});

Performance monitoring

Register the filter below and every request also times its own duration, bucketed by transaction (Spring MVC's own matched handler pattern when running under Spring, e.g. "GET /users/{id}", not the raw URI; falls back to the raw URI for a plain servlet app) and flushed as a small periodic aggregate every 60 seconds, the same delivery philosophy as release health above. Requires a plan that includes performance monitoring; on a plan that doesn't, the periodic reports are accepted but not recorded (the response says why), so a working setup never looks broken. Each report also carries a small latency histogram (version 0.7.0 and later), so ForgeOps shows an approximate p50/p95/p99 per transaction, not just an average, accurate to the width of the latency bucket a duration falls into.

The Performance page, showing each transaction's request count and p50, p95 and p99 latency, plus slow queries
import io.github.lukepopwell.tracker.integrations.servlet.ForgeOpsTrackerPerformanceTrackingFilter;

new ForgeOpsTrackerPerformanceTrackingFilter(); // order relative to the other filters doesn't matter

ForgeOpsTracker.init(config -> {
  config.setTrackPerformance(false); // opt out entirely
  config.setPerformanceFlushInterval(
      Duration.ofSeconds(30)); // default 60
});

Distributed tracing

The performance tracking servlet filter starts a trace for every request, so the request itself is always the root span. Only a slow request's trace is ever sent: whether it crossed the threshold (one second by default, configurable) is decided entirely inside your process, so a fast request costs nothing over the wire. Wrap the database calls, HTTP calls, and service code you care about to see where the time went. Requires a plan that includes distributed tracing.

A trace's waterfall for one slow request, with its controller, service, database, cache and HTTP spans
Order order = ForgeOpsTracker.span("charge card", "service", Map.of("orderId", id), () -> gateway.charge(id));
ForgeOpsTracker.span("render", () -> view.render()); // kind defaults to "service"

// Something you timed yourself (kind is one of controller/service/database/redis/http/job/other):
ForgeOpsTracker.recordSpan("SELECT orders", "database", startedAt, durationMs, Map.of());

Errors now carry the request they happened in: its endpoint (POST /checkout) and its trace id. An issue names its affected endpoint, each occurrence links to its exact trace, and a request that fails is always traced, however fast. With the servlet filters or Spring, a request that arrives with the standard traceparent header continues the caller's trace on its own; pass it on by wrapping an outbound call in httpSpan, which records it as an http span and hands you the headers to add, with any HTTP client. Once the projects are linked in ForgeOps an error shows the errors another project raised in the same request. Needs io.github.luke-popwell:tracker 0.9.0.

One trace waterfall running from a mobile app's checkout tap into the API it called, with the API's controller, database, and payment calls nested underneath, each project labeled
HttpResponse<String> response = ForgeOpsTracker.httpSpan("POST", paymentsUri, headers -> {
  HttpRequest.Builder request = HttpRequest.newBuilder(paymentsUri).POST(BodyPublishers.ofString(body));
  headers.forEach(request::header);
  return httpClient.send(request.build(), HttpResponse.BodyHandlers.ofString());
});

ForgeOpsTracker.init(config -> {
  config.setTracePropagationTargets(List.of("api.example.com")); // only these hosts; null (the default) means all
});

SQL in a request

When the request an issue failed in was traced, the issue opens with its slowest query: how long it took, its share of the request's time, how many queries the request ran, and a likely N+1 warning when the same statement ran five or more times. JDBC isn't instrumented automatically, so wrap a query in databaseSpan and pass its SQL; bind values are never read. The statement is masked before it leaves your process, every string and number replaced with a question mark, and the same SQL shows under that span's bar in the trace's waterfall. Needs io.github.luke-popwell:tracker 0.11.0, on a plan that includes distributed tracing.

An issue's Slowest query in this request card: a 2.7 second order search that took 86% of a 3.2 second request, a likely N+1 warning for a line_items query run 24 times, and the query plan calling out a sequential scan on orders
static final String OPEN_ORDERS = "SELECT id FROM orders WHERE customer_id = ? AND status = 'open'";

List<Long> ids = ForgeOpsTracker.databaseSpan("Load open orders", OPEN_ORDERS, "postgresql", () -> {
  try (Connection connection = dataSource.getConnection();
      PreparedStatement statement = connection.prepareStatement(OPEN_ORDERS)) {
    statement.setLong(1, customerId);
    List<Long> found = new ArrayList<>();
    try (ResultSet rows = statement.executeQuery()) {
      while (rows.next()) found.add(rows.getLong("id"));
    }
    return found;
  }
});
// Sent as "SELECT id FROM orders WHERE customer_id = ? AND status = ?"

What changed

A feature flag flip or a config edit can break things with no deploy at all. Record one with recordChange and it shows under What changed on any issue that starts in the next two hours, and on the project's Changes page beside your deploys, labeled potentially relevant, never as the cause. init() also sends the Java runtime version once per process from a background thread, so a JVM upgrade shows up with nothing to call; library versions are left out, since a classpath has no reliable record of them. Environment variable names (never values) are opt-in. Needs io.github.luke-popwell:tracker 0.10.0, on a plan that includes change tracking.

An issue's verdict listing what changed just before it started, labeled potentially relevant: the gateway_retry_v2 flag turned on for 100% of checkouts 3 minutes before, and a stripe upgrade and a new environment variable detected at startup after the deploy 7 minutes before
ForgeOpsTracker.init(config -> {
  config.setDetectChanges(true);    // the default; false sends no startup snapshot
  config.setTrackEnvVarNames(true); // default false; names only, never values
});

ForgeOpsTracker.recordChange(
    Change.of("feature_flag", "gateway_retry_v2 turned on for 100% of checkouts")
        .details(Map.of("flag", "gateway_retry_v2", "from", "10%", "to", "100%"))
        .actor("priya@example.com"));

Custom metrics and infrastructure monitoring

Track a business event you name yourself (a signup, a payment) or a reading from one of your own hosts, with one explicit call each; nothing is automatic. The value defaults to 1, so a bare call is a counter; pass a real amount for anything else (it can be negative, for a refund). A captured value is stored as its own row, so counts and sums you compute later are exact. Calls are buffered and flushed as one batch in the background, so they are safe to make inside a request, and flushMetrics sends whatever is buffered right now. The hostname of an infrastructure reading defaults to the configured server name. Requires a plan that includes custom metrics and infrastructure monitoring.

A dashboard with custom-metric widgets (orders placed, checkout conversion, orders over time) and infrastructure widgets (average readings by host and by metric)
ForgeOpsTracker.captureMetric("signup"); // value defaults to 1: a bare counter
ForgeOpsTracker.captureMetric("payment", 49.0); // a real magnitude; it may be negative (a refund)

ForgeOpsTracker.captureInfrastructureMetric("cpu", 0.42); // hostname defaults to serverName
ForgeOpsTracker.captureInfrastructureMetric("disk", 0.81, "db-1");
ForgeOpsTracker.flushMetrics(); // optional: send right now

Database errors

When an error comes from a database call, the issue shows which stored procedure, table or view its SQL touched, so you know where to start looking. Hibernate's JDBCException and Spring's BadSqlGrammarException expose the statement through getSQL() or getSql(), read by reflection so the client depends on neither. Plain JDBC exceptions carry none. The names are sent by default and are identifiers, never values. The SQL statement itself is opt-in, with every string and number replaced by a question mark before it leaves your app, and a project setting can stop ForgeOps storing the statement at all.

An issue occurrence's Database section, naming the stored function and the view the failing query touched, with the statement's values replaced by question marks
ForgeOpsTracker.init(config -> {
  config.setDsn("...");
  config.setCaptureSqlStatement(true); // default false
  // config.setCaptureSqlObjects(false); // default true; false stops even the names
});

Questions

Do I need to change how I already handle errors?

Almost never. Every client hooks the framework's own exception handling directly, the same way the install snippet above shows, so your own logs, error pages, and rescue blocks keep working exactly as they did before, and ForgeOps just also finds out about it. The one common exception is a background-job runner that doesn't forward through that same mechanism on its own; that needs one small hook added instead, not a change to anything already there.

Where does the data actually go?

Straight to ForgeOps' own ingestion API over plain HTTPS. No agent, no sidecar, and no third-party ingestion service in between, so nothing about your app's traffic or its users' data gets routed through anyone else's pipeline first.

What happens if the same bug fires a thousand times?

It's fingerprinted from its exception class, message, and backtrace, so a thousand reports of the same bug still show up as one issue with an event count of 1,000, not a thousand separate rows to dig through. And a runaway loop can't use up your monthly event quota: once one issue repeats faster than your plan's hourly limit (50 an hour on Free), further repeats are still counted, and still count toward spike alerts, but they aren't stored or charged to your quota.

Is anything scrubbed before it's stored?

Yes. Emails, credit card numbers, and known API key/token formats are redacted out of every event before it's even written, on every plan, with room for per-project custom field names on top of the defaults.

Try it with your own Java app

Free plan included, no credit card required. New organizations start with 14 days of Business.

Get started free