Splunk Dashboard: Application Report

Application-centric PQC readiness, risk, and supporting operational detail.

The Application Report dashboard provides an application-centric view of post-quantum cryptography readiness. It combines readiness metrics with operational details, allowing analysts to evaluate key exchange, TLS protocol adoption, certificate signature posture, cryptographic risks, and supporting application and certificate information.

Default time range: Last 30 days Primary focus: Service-application cryptographic readiness, risk, and supporting detail records

Operational guidance: Begin with the readiness summary to understand overall application compliance, then review risk and usage panels to identify technologies requiring modernization. Use the detailed application, certificate, and DoD OMB reporting tables to investigate individual findings.

Panels

Panel Type What It Shows
Post-Quantum Cryptography ReadinessTableKey-exchange technologies grouped by PQC READY, MODERN, CLASSICAL, and LEGACY tiers, with counts.
Application PQC DashboardReadiness summaryApplication compliance indicators for key exchange, TLS protocol, and certificate signatures, including percentages and application counts.
Certificate SignatureTableCertificate-signature technologies grouped by readiness tier, with counts.
Web Server DistributionStacked bar chartDistribution of web-server families by PQC key-exchange tier.
Weak Ciphers In UseTableWeak cipher algorithms currently observed and the number of applications associated with each.
Insecure Ciphers In UseTableInsecure cipher algorithms currently observed and the number of applications associated with each.
Port UsageTableObserved ports divided between quantum-resilient and not-resilient activity.
Vulnerable SoftwareTableSoftware packages identified as not quantum ready.
Non-Quantum Ready KXTableKey-exchange technologies that do not match recognized post-quantum patterns.
Non-Quantum Ready SignaturesTableSignature technologies that do not match recognized post-quantum patterns.
Application DetailTableDetailed application cryptography inventory, including key exchange, cipher suite, protocol, readiness, host, port, and certificate information.
Certificate DetailTableCertificate subjects, counts, issuance and expiration dates, remaining time, lifespan, curve, algorithm, and key size.
DoD OMB Report DetailTableDetailed DoD OMB reporting fields for software, algorithms, protocols, certificates, cryptographic parameters, and timestamps.

Key Data Fields

Field Description
process.executable / process.nameIdentifies the service application used in application-level reporting and filtering.
omb.kex_tierProvides the key-exchange readiness tier.
omb.protocol_tierProvides the TLS protocol readiness classification.
omb.sig_tierProvides the certificate-signature readiness tier.
tls.supported_ciphersLists supported TLS cipher suites used in detailed reporting.
tls.kxIdentifies the preferred key-exchange technology.
x509.subject.distinguished_nameIdentifies the certificate subject shown in Certificate Detail.
certificate.not_before / certificate.not_afterProvide certificate issuance and expiration dates.
certificate.subject_public_key_info.algorithm / x509.server.port / destination.port / host_idSupport algorithm, port, and host-level detail used throughout the dashboard.

Reading the Dashboard

Start with the readiness summary

Compare key-exchange, protocol, and certificate-signature compliance for service applications.

Review application risk and usage

Examine web-server distribution, weak and insecure ciphers, port usage, vulnerable software, and non-quantum-ready key exchange and signatures.

Investigate detailed records

Use Application Detail for application-level cryptography, Certificate Detail for certificate lifecycle and key information, and DoD OMB Report Detail for the complete reporting record.

Expect certificate gaps in some filters

Application, key-exchange, and protocol selections can legitimately produce no Certificate Detail results when those fields are not present in the certificate events.

Filtering and Implementation Notes

Use the Time Range, Key Exchange, TLS Protocol, Cert Signature, and Application filters to focus the dashboard. Category filters default to All and apply across the dashboard.

The Certificate Detail table depends on certificate records, so some valid application-level filters can return no certificate rows.