Splunk Dashboard: Certificate Report

Certificate health, cryptographic posture, and renewal or remediation priorities.

The Certificate Report dashboard provides a consolidated view of certificate inventory, validity, cryptographic strength, issuer distribution, and post-quantum readiness. It combines certificate health indicators with algorithm, key-size, longevity, source, and detailed inventory information.

Default time range: Last 30 days Primary focus: Certificate health, cryptographic posture, and renewal or remediation priorities

Operational guidance: Begin with the summary indicators to understand the size and immediate risk of the certificate population. Review Certificate Signature and Certificate Hygiene for readiness and lifecycle issues, then examine issuing authorities, algorithms, key sizes, longevity, and the detailed certificate records.

Panels

Panel Type What It Shows
TotalSingle valueTotal certificate records in the filtered population.
ExpiredSingle valueCertificates whose expiration date has passed.
Exp 30DSingle valueCertificates scheduled to expire within 30 days.
Self-SignedSingle valueCertificates identified as self-signed.
LegacySingle valueCertificates classified in the legacy signature tier.
PQC VulnSingle valueCertificates identified as PQC-vulnerable or not classified as PQC ready.
Certificate SignatureTableSignature readiness categories, representative algorithms, counts, and percentages.
Certificate HygieneTableExpired, near-expiration, self-signed, and weak-key findings with severity and prevalence.
Top Issuing CAsBar chartMost frequently observed issuing certificate authorities.
Key AlgorithmTablePublic-key algorithms with descriptions, counts, and percentages.
Key Size DistributionTablePublic-key sizes with strength classifications, counts, and percentages.
Signature AlgorithmTableObserved certificate signature algorithms and readiness tiers.
Certificate LongevityTableCertificate lifetime and expiration-window information.
Certificate SourceTableCertificate records grouped by source type.
Certificate DetailTableDetailed certificate inventory for investigation and remediation planning.

Key Data Fields

Field Description
observer.hostnameHost associated with the certificate record.
tychon.typeCertificate source category.
omb.sig_tierCertificate-signature readiness tier.
certificate.key_algorithm / certificate.key_bit_sizeCertificate public-key algorithm and key size.
certificate.chain[] / signature_algorithmChain and signature fields used for issuer and hygiene analysis.
x509.issuer.common_nameIssuing certificate authority.
certificate.not_before / certificate.not_afterCertificate validity start and expiration dates.
x509.subject.distinguished_nameCertificate subject distinguished name.

Reading the Dashboard

Review the KPI row first

Use the summary metrics to gauge immediate certificate risk and scope.

Compare signature readiness and hygiene

These panels surface lifecycle issues alongside post-quantum concerns.

Review issuing CAs and key attributes

This helps identify concentration and weak cryptographic configurations.

Use longevity and detail for remediation

Plan renewals from the longevity views, then investigate individual records in Certificate Detail.

Filtering and Implementation Notes

Use the Time Range, Host, Certificate Source, Signature Tier, Key Algorithm, Key Size, Signature Algorithm, Issuing CA, and Self-signed controls. All category filters default to All.

These filters combine to narrow the certificate population for focused investigation and remediation planning.