Insights Dashboard

Fleet health overview — node status, app coverage, certificate alerts, and Splunk version distribution

Insights Dashboard

The Insights Dashboard gives you a single-pane view of your Splunk fleet's health — node status, Splunk version distribution, cluster health, app coverage, and certificate expiration alerts.


Fleet Summary

Navigate to Automation PlatformInsights to see the fleet dashboard. The top-level cards show:

Node Status

MetricDescription
TotalAll enrolled nodes
OnlineNodes that checked in recently
StaleNodes that haven't checked in within the expected window
OfflineNodes that are unreachable

Splunk Version Distribution

A breakdown of Splunk Enterprise versions across your fleet, showing how many nodes run each version. Helps you identify hosts that need upgrades.

Cluster Health

MetricDescription
Clustered hostsTotal hosts in index or search head clusters
RF not metReplication factor violations
In maintenanceHosts in maintenance mode
Rolling restart activeClusters undergoing rolling restart
Bundle issuesKnowledge bundle replication problems
SHC not readySearch head cluster members not ready

Certificate Alerts

SeverityDescription
ExpiredCertificates past their expiration date
CriticalExpiring within 7 days
WarningExpiring within 30 days
AdvisoryExpiring within 90 days
HealthyValid certificates with no upcoming expiration

App Inventory

Navigate to InsightsApps to see a cross-fleet app inventory. For each Splunk app, you see:

  • App name and configuration stanza count
  • Installed on — which hosts have the app
  • Missing from — which hosts do not
  • Coverage — percentage of enrolled hosts with the app installed
  • Last seen — when the app was last detected

Expand any app row to see the full list of hosts where it is installed or missing.

Certificate Monitor

Navigate to InsightsCertificates to view all TLS certificates across your fleet. Filter by severity level and search by hostname, subject, or file path. Each certificate shows:

  • Host, file path, subject, and issuer
  • Validity dates and days remaining
  • Severity badge (Expired, Critical, Warning, Advisory, or Healthy)
  • Whether it is a default Splunk certificate or CA certificate
Insights Dashboard | Deslicer AI Docs