Splunk Dashboard: Application Topology Explorer

Host and application relationship analysis with selection context and aggregate PQC risk.

The Application Topology Explorer dashboard explores relationships between hosts and applications while also presenting application-level PQC readiness and aggregate risk. It helps users determine which applications run on selected hosts, which hosts run selected applications, and how the selected population performs across key exchange, TLS protocol, and certificate-signature readiness.

Default time range: Last 30 days Primary focus: Host/application relationships, selection context, and PQC risk

Operational guidance: Use the Host and Application filters to move between host context and application context. Confirm the current selection, review the related hosts or applications, and then use the readiness and risk panels to assess the cryptographic posture of that selected population.

Panels

Panel Type What It Shows
Current Selection DetailsTableDisplays the active context, selection, representative source host, application, destination, protocol, TLS version, cipher, event count, and first/last observed times.
Current Filter SelectionTableShows the currently selected Host and Application filter values.
Applications Installed on Selected HostTableApplications associated with the selected host and the number of observed relationship records.
Hosts Running Selected ApplicationTableHosts associated with the selected application and the number of observed relationship records.
Relationship OverviewTableSummary counts of hosts, applications, and relationship events in the filtered population.
Host Context SummaryTableTop hosts ranked by related application count and relationship activity.
Application Context SummaryTableTop applications ranked by related host count and relationship activity.
Application PQC DashboardReadiness summaryApplication compliance progress for PQC-ready key exchange, TLS 1.3 capability, and PQC-ready certificate signatures.
Aggregate Risk DeterminationDonut chartRisk score derived from the inverse of average application readiness across key exchange, protocol, and signature dimensions.

Key Data Fields

Field Description
hostHost associated with an application relationship.
process.nameApplication name used for topology relationships.
process.executableApplication executable used for readiness analysis when available.
destination.ipObserved destination associated with the selected context.
network.protocol / tls.version / tls.cipherObserved network protocol, TLS version, and cipher.
omb.kex_tier / omb.protocol_tier / omb.sig_tierKey-exchange, TLS protocol, and certificate-signature readiness tiers.

Reading the Dashboard

Select a host or application

The filters define whether you are moving through host context or application context.

Confirm the selection details

Check the active filter state and representative relationship details before drawing conclusions.

Review both relationship tables

Use them to see the corresponding applications or hosts connected to the current selection.

Use Aggregate Risk Determination last

This summarizes the overall risk of the filtered application population after you understand the context.

Filtering and Implementation Notes

Use the Time Range, Application, and Host controls. Application and Host default to All.

Selecting a Host populates the host-context relationship table, selecting an Application populates the application-context relationship table, and leaving both broad shows overview panels for the full filtered population.