Automation Platform
Observe, automate, and govern Splunk configuration changes across your fleet with Deslicer Automation Platform (DAP)
Automation Platform
Deslicer Automation Platform (DAP) gives you centralized visibility and control over Splunk configuration changes across your entire fleet — from forwarders and indexers to search heads and deployment servers.
Navigation
- Parent: Documentation Home
- Related: Deslicer Observer API | App Deployment Agent
Pages in This Section
| Page | Description |
|---|---|
| Getting Started with DAP | Provisioning, enrollment tokens, and enrolling your first node |
| Platform Planes | Shared DAP status, Splunk Enterprise worker plane, and product-scoped navigation |
| Splunk Execution Credentials | Management credentials DAP workers use when executing approved plans |
| Pending Approvals | Review and approve enrollment requests before hosts join the fleet |
| Inventory Groups | Assign enrolled hosts to Splunk roles with configuration-driven suggestions |
| API Keys | Create and manage Observer API keys for DAP integrations and AI agents |
| Insights Nodes | Enrolled hosts, operational state, and fleet visibility |
| Change Plans | Create, review, approve, and execute configuration changes |
| Executions | Track plan execution history, live status, and per-job results |
| Insights Dashboard | Fleet health, app inventory, certificate monitoring, and Splunk version distribution |
| Configuration Browser | Search and inspect Splunk configurations across all enrolled nodes |
| Enterprise Inventory | Manage fleet topology, host groups, role assignments, and inventory templates |
Overview
DAP connects to your Splunk hosts via lightweight Insights Nodes — agents that report operational state, configuration snapshots, and certificate status back to the platform. You manage everything from the Automation Platform section in the dashboard sidebar.
What You Can Do
- Observe — See every enrolled Splunk host, its version, last check-in time, installed apps, and configuration details
- Automate — Create change plans that bundle configuration changes, push them to nodes, and track execution
- Govern — Approve or reject change plans before execution, review execution logs, and monitor rollout status
- Monitor — Track fleet health with app coverage, certificate expiration alerts, and Splunk version distribution
How It Works
- Provision DAP — one-click provisioning from Platform → DAP Status connects your tenant to the Observer API
- Open a worker plane — use Platform → Splunk Enterprise for install snippets, enrollment, credentials, nodes, and inventory (see Platform Planes)
- Create enrollment tokens — generate Insights or Worker tokens to authenticate new hosts
- Enroll nodes — run the install command on each Splunk host (Insights add-on or Worker bootstrap)
- Approve enrollments — when policy requires it, review pending requests on Pending Approvals
- Assign inventory roles — map enrolled hosts to Splunk roles on Inventory Groups
- Create API keys — generate Observer API keys from Platform → API Keys
- Configure Splunk credentials — add management credentials workers use when executing approved plans (see Splunk Execution Credentials)
- Manage from the dashboard — use Observe and Automate to monitor fleet health, browse configs, create change plans, and track executions
- Self-repair — if connectivity degrades, use Reconnect Integration on DAP Status to restore the connection without losing data
Start with Getting Started with DAP to provision your tenant and enroll your first node.