This dashboard monitors PKI CA-event freshness, certificate activity, errors, and quantum readiness. Its Active, Stale, and Failed labels describe event age; Failed does not by itself establish an authentication or connector failure.
Panels
| Panel | Purpose |
|---|---|
| Integration Health Summary | Summarizes CA-event timestamps, scan age, platform status, and counts for the selected population. |
| Platform Scan Freshness | Groups CA records by age: Active below 6 hours, Stale from 6 to less than 24 hours, and Failed at 24 hours or more. |
| Event Volume Trend | Shows CA-event activity over time for the selected platforms. |
| Error and Warning Log | Displays events marked as errors or warnings and their emitted error messages. |
| CA Count Over Time | Shows CA certificate counts over time for the selected platforms. |
| Per-Platform Quantum Readiness Score | Shows the percentage of CA certificates marked quantum-ready for each platform. |
Key Data Fields
event.action=pki_ca_discovered, event.created, tychon.pki.platform.type, tychon.pki.platform.host, tychon.pki.ca.*, x509.serial_number, event.type, event.severity, error.message.
Reading the Dashboard
Integration Health Summary
Summarizes CA-event timestamps, scan age, platform status, and counts for the selected population.
Platform Scan Freshness
Groups CA records by age: Active below 6 hours, Stale from 6 to less than 24 hours, and Failed at 24 hours or more.
Event Volume Trend
Shows CA-event activity over time for the selected platforms.
Error and Warning Log
Displays events marked as errors or warnings and their emitted error messages.
CA Count Over Time
Shows CA certificate counts over time for the selected platforms.
Per-Platform Quantum Readiness Score
Shows the percentage of CA certificates marked quantum-ready for each platform.
Splunk derives age from event.created, falling back to _time when needed. Records with no usable timestamp are labeled Unknown. Integration Health Summary counts distinct x509.serial_number values and can show multiple age-based statuses within a platform. Its Hours Since Scan value is the maximum age among the selected records, so older retained records can affect that value.
The inventory and freshness panels use event.action=pki_ca_discovered. A platform with no matching CA events in the selected time range may be absent. These panels do not distinguish a successful empty scan from a failed scan that returned no certificates. The scanner reports connector outcomes separately through event.action=pki_scan_completed in event.dataset=pki_scan_health.
Filtering and Performance
Use the dashboard time range and global filters to narrow the population before interpreting counts. Preserve host, application, platform, algorithm, and risk filters when moving to related dashboards. Aggregations summarize the filtered events; missing optional fields mean that a value was not emitted or observed, not that the condition is false.
Related Dashboards
Use the overview page to move between this dashboard and the other dashboard definitions.