Splunk Dashboard: Crypto Libraries

Inventory crypto libraries, versions, capabilities, and remediation exposure.

This dashboard answers which cryptographic libraries are installed or loaded, which versions are present, and where vulnerable or non-PQC-capable libraries require remediation.

Panels

PanelPurpose
Library InventoryEstablishes library population, ownership, versions, and discovery coverage.
Vulnerable LibrariesPrioritizes libraries with known vulnerabilities, CVEs, or unacceptable risk levels.
Version DistributionShows version concentration and coordinated upgrade opportunities.
Library DetailIdentifies the exact host, process, path, and version requiring remediation.

Key Data Fields

tychon.library.name, tychon.library.openssl_version, tychon.library.crypto_type, tychon.library.pqc_status, observer.hostname, observer.os.*.

Reading the Dashboard

Library Inventory

Establishes the discovered library population by host, path, vendor, and version. Use this as the scope check before interpreting risk counts.

Vulnerable Libraries

Highlights libraries associated with weak, vulnerable, or quantum-vulnerable crypto capability. Prioritize hosts and versions that recur across the filtered events.

Version Distribution

Shows concentration by version and vendor so upgrade planning can target the versions with the broadest deployment footprint.

Library Detail

Provides the path, owning application, detection source, and version evidence needed to validate and remediate an individual library finding.

Filtering and Performance

Use the dashboard time range and global filters to narrow the population before interpreting counts. Preserve host, application, platform, algorithm, and risk filters when moving to related dashboards. Aggregations summarize the filtered events; missing optional fields mean that a value was not emitted or observed, not that the condition is false.

Related Dashboards

Use the overview page to move between this dashboard and the other dashboard definitions.