Elasticsearch Dashboard: Cost Analysis

PQC migration cost estimates, labor effort, and upgrade priorities.

The Cost Analysis dashboard helps program managers, security leaders, and migration planners estimate PQC upgrade budgets and effort. It combines an executive cost summary with OS and application-family breakdowns so teams can compare expenditure, affected populations, and cryptographic risk.

Default time range: One year Data source: tychon-pqc-system-readiness* Currency: USD

Panels

PanelTypeWhat It Shows
Executive Cost SummaryVega scorecardsTotal upgrade cost, labor hours, assets requiring upgrade, and labor, hardware, and license/software costs. Per-asset figures and component percentages provide additional context.
Effort vs. RiskVega bubble chartCompares estimated upgrade cost on the horizontal axis with LEGACY and CLASSICAL tiers on the vertical axis. Color distinguishes OS and application upgrades; bubble size represents the affected population.
OS Upgrade Cost EstimateInteractive Vega ranked listShows up to 30 OS categories ranked by estimated OS upgrade cost, with labor hours, license cost, hardware cost, and the most frequent tier. Click an OS row to apply a category filter.
PQC Cost Composition by App FamilyVega stacked barsShows the ten highest-cost application families with positive total cost, split into labor, license, and hardware components.
Priority Matrix (Top App Families)Vega heatmapCompares estimated cost by application family and tier for the ten highest-cost families among the retrieved buckets. The visible tier columns are LEGACY and CLASSICAL; tooltips include affected instances.
Navigation LinksDashboard linksOpens other Quantum Command dashboards for posture and application investigation.

Key Data Fields

FieldDescription
event.datasetOS estimates use quantum_assessment; application-family estimates use quantum_assessment.app_group.
@timestampTime field used by the panels.
quantum_readiness.cost_analysis.total_cost_usdEstimated total upgrade cost in US dollars; also used to count records with cost values in the executive summary.
quantum_readiness.cost_analysis.total_labor_hoursEstimated total labor hours in the executive summary.
quantum_readiness.cost_analysis.total_labor_cost_usd
quantum_readiness.cost_analysis.total_hardware_cost_usd
quantum_readiness.cost_analysis.total_license_cost_usd
Executive cost components. All three names use the quantum_readiness.cost_analysis prefix.
quantum_readiness.cost_analysis.os_category
quantum_readiness.cost_analysis.os_tier
Operating-system category and its cryptographic readiness tier.
quantum_readiness.cost_analysis.os_total_cost_usd
quantum_readiness.cost_analysis.os_labor_hours
quantum_readiness.cost_analysis.os_hardware_cost_usd
quantum_readiness.cost_analysis.os_license_cost_usd
OS-specific cost and effort values, under the same cost_analysis prefix.
quantum_readiness.cost_analysis.app_family
quantum_readiness.cost_analysis.tier
quantum_readiness.cost_analysis.instance_count
Application family, readiness tier, and affected instance count, under the same cost_analysis prefix.
quantum_readiness.cost_analysis.labor_cost_usd
quantum_readiness.cost_analysis.license_cost_usd
quantum_readiness.cost_analysis.hardware_cost_usd
Application-family cost components, under the same cost_analysis prefix.

Reading the Dashboard

Establish the budget and population

Start with total upgrade cost and labor hours, then inspect the three component totals. Assets Requiring Upgrade counts records with a total-cost value; it is not a unique-host count or a count restricted to positive costs. A zero-cost record can contribute to this count.

Compare effort with risk

Use the bubble chart to compare expensive upgrades with lower-cost work at the same risk tier. Only positive-cost items are included. OS bubble size uses document count; application bubble size uses summed instance_count, with a fallback of one when that sum is unavailable or zero. The displayed tier is the most frequent tier for that category or family.

Investigate an OS upgrade

Use the ranked OS list to review cost and labor together. Clicking a row adds an os_category filter to Kibana. That filter also affects the other panels and can exclude application-family records without that field; clear it before returning to the full migration budget.

Plan application-family work

Use the component chart to identify whether labor, licensing, or hardware dominates an application upgrade. Use the matrix to compare LEGACY and CLASSICAL work within the selected families. Hover for full names, cost, and instance counts; shortened labels are for display.

Filtering and Interpretation

The saved dashboard opens with a one-year time range (now-1y/d to now). All cost panels use @timestamp and the Kibana query, time range, and global filters. They sum matching records without selecting only the latest record per asset. Repeated scans in the selected period can therefore increase costs and counts; choose a period and filters that represent the assessment population you intend to budget.

Costs come from the scanner’s precomputed cost_analysis fields. These are estimates for planning, not measured expenditure. Missing numeric values do not contribute to sums and can leave zero totals; a blank or zero result does not establish that no upgrade is needed. The OS and application charts use bounded category/family aggregations, and the application charts show only the top ten families. Their visible subtotals need not match the executive total.