Monitorring is always one of those topics, IMHO, that's highly debatable. How far do you go, and where do you stop?
In my company, I've opted to monitor for the following:
1. Application Server server status - Verifies if there's a PID files, that the PID is linked to a java process, then launches the serverStatus shell script. This is done for ALL application servers
2. Core / Heap files - look in the profile directory to see if there's a heap dump... Very helpful in understanding why your other checks may have spiked. Besides, who wants large files consuming disk space???
3. Session Size
4. Heap Split (used, free)
5. Heap Size
6. JDBC Connection Pool size
7. Free disk space
8. General server process - Overall CPU, Memory, OS partition, Data Drive Partition
9. Don't forget to turn on Verbose GC
I monitor my HTTP deployment in a very similar fashion as well.
In my setup, I leverage Nagios, Nagios Graph, DRRaw, & NSC++ to monitor my systems, render graphs, keep 12 months of data in an RRD, and propogate alerts.
The best parts of the above approach is
1. The ENTIRE implimentation is 100% free!
2. It only took about two weeks to stand up the implimentation.
3. I have great insight into everything.
Good Luck!
Erik