Elasticsearch Dashboard: Quantum Command Inventory

Fleet-level PQC readiness across hosts, protocols, signatures, and operating systems.

The Quantum Command Inventory dashboard gives program managers, security leaders, and analysts an authoritative fleet-level view of PQC migration progress. It answers a central question: across all observed endpoints, how many are PQC-ready, modern, classical, or legacy?

Use this dashboard to establish overall posture, compare readiness across operating systems, identify the largest legacy populations, and apply tier filters before moving into application-level investigation.

Default time range: Last 90 days Data source: tychon-pqc-inventory*

Operational guidance: Use the three interactive tier charts together. Key exchange, protocol, and certificate signature represent separate migration dimensions; improvement in one dimension does not guarantee that an endpoint is fully quantum-ready.

Panels

Panel Type What It Shows
Navigation Links BarLinksOpens the other Quantum Command dashboards without returning to the Elasticsearch dashboard listing.
PQC Compliance Progress MapVega summaryShows unique host counts at the PQC READY tier with operating-system and key-exchange context.
Crypto Posture ScoreVega scorecardProvides an executive readiness score across the key exchange, protocol, and certificate-signature dimensions, with an OS-platform breakdown.
Key Exchange TierInteractive Vega chartBreaks unique hosts into PQC READY, MODERN, CLASSICAL, and LEGACY key-exchange tiers. Selecting a tier filters the dashboard.
TLS Protocol TierInteractive Vega chartShows unique hosts using TLS 1.3, TLS 1.2, or legacy protocol versions. Selecting a tier filters all panels.
Certificate Signature TierInteractive Vega chartGroups unique hosts by PQC-ready, modern, classical, or legacy certificate-signature algorithms.
Windows WorkstationsOS breakdownShows key-exchange, protocol, and signature tier distributions for Windows workstation endpoints.
Windows ServerOS breakdownShows all three readiness dimensions for Windows Server endpoints.
macOSOS breakdownShows all three readiness dimensions for macOS endpoints.
CentOSOS breakdownShows all three readiness dimensions for CentOS endpoints.
Red Hat Enterprise LinuxOS breakdownShows all three readiness dimensions for RHEL endpoints.
UbuntuOS breakdownShows all three readiness dimensions for Ubuntu endpoints.

Key Data Fields

Field Description
omb.kex_tierKey-exchange readiness tier: PQC READY, MODERN, CLASSICAL, or LEGACY.
omb.protocol_tierTLS protocol tier: TLS 1.3, TLS 1.2, or LEGACY.
omb.sig_tierCertificate-signature readiness tier: PQC READY, MODERN, CLASSICAL, or LEGACY.
host.idUnique endpoint identifier used for host cardinality calculations.
host.os_categoryNormalized OS category used by the six platform panels.

Reading the Dashboard

Begin with the Crypto Posture Score

Use the composite score as an executive indicator, then validate it against the three independent tier charts.

Prioritize LEGACY populations

Select LEGACY in the key-exchange or certificate-signature chart to isolate endpoints requiring the most immediate remediation.

Compare OS categories

Use the six platform panels to determine whether risk is concentrated in a particular operating system or distributed across the fleet.

Count hosts, not records

All tier values use unique host counts so repeated scans do not inflate the reported endpoint population.

Filtering and Performance

The dashboard opens with a default time range of Last 90 days. Global Elasticsearch dashboard filters apply to the panels unless a panel description states otherwise. Preserve relevant filters when navigating between related dashboards so the investigation remains scoped to the same application, host, tier, or certificate population.