In many case, the issue can be mitigated just by launching the application with the -Dlog4j2.formatMsgNoLookups=true flag. This is what ElasticSearch did in their 7.16.1 release (note that ElasticSearch wasn't vulnerable due to how it's implemented, but they still added that startup flag just to be 100% safe).
That was the extent of what I had to deal with for my customers: two servers running recent ElasticSearch, updated to the latest versions. I spent more time scanning servers than actually fixing them.