Elasticsearch Dashboard: CAMP Integration Health

Connector freshness, platform coverage, scan status, and discovery failures.

This dashboard monitors PKI CA-event freshness, certificate activity, errors, and quantum readiness. Its Active, Stale, and Failed labels describe event age; Failed does not by itself establish an authentication or connector failure.

Panels

PanelPurpose
Integration Health SummarySummarizes CA-event timestamps, scan age, platform status, and counts for the selected population.
Platform Scan FreshnessGroups CA records by age: Active below 6 hours, Stale from 6 to less than 24 hours, and Failed at 24 hours or more.
Event Volume TrendShows CA-event activity over time for the selected platforms.
Error and Warning LogDisplays events marked as errors or warnings and their emitted error messages.
CA Count Over TimeShows CA certificate counts over time for the selected platforms.
Per-Platform Quantum Readiness ScoreShows the percentage of CA certificates marked quantum-ready for each platform.

Key Data Fields

event.action=pki_ca_discovered, event.created, tychon.pki.platform.*, tychon.pki.ca.*, x509.serial_number, hours_since_scan, platform_status, event.type, event.severity, and error.message.

Reading the Dashboard

Integration Health Summary

Summarizes CA-event timestamps, scan age, platform status, and counts for the selected population.

Platform Scan Freshness

Groups CA records by age: Active below 6 hours, Stale from 6 to less than 24 hours, and Failed at 24 hours or more.

Event Volume Trend

Shows CA-event activity over time for the selected platforms.

Error and Warning Log

Displays events marked as errors or warnings and their emitted error messages.

CA Count Over Time

Shows CA certificate counts over time for the selected platforms.

Per-Platform Quantum Readiness Score

Shows the percentage of CA certificates marked quantum-ready for each platform.

Elasticsearch uses the hours_since_scan and platform_status runtime fields derived from event.created. A missing timestamp is treated as stale enough to produce Failed. Integration Health Summary shows the latest event timestamp and status, the minimum age among the selected records, and a raw record count. The panel labels that minimum age as Avg Hours Since Last Scan; it is not an average.

The inventory and freshness panels use event.action=pki_ca_discovered. A platform with no matching CA events in the selected time range may be absent. These panels do not distinguish a successful empty scan from a failed scan that returned no certificates. The scanner reports connector outcomes separately through event.action=pki_scan_completed in event.dataset=pki_scan_health.

Filtering and Performance

Use the dashboard time range and global filters to narrow the population before interpreting counts. Preserve host, application, platform, algorithm, and risk filters when moving to related dashboards. Aggregations summarize the filtered documents; missing optional fields mean that a value was not emitted or observed, not that the condition is false.

Related Dashboards

Use the overview page to move between this dashboard and the other dashboard definitions.