Automation Platform

Observe, automate, and govern Splunk configuration changes across your fleet with Deslicer Automation Platform (DAP)

Automation Platform

Deslicer Automation Platform (DAP) gives you centralized visibility and control over Splunk configuration changes across your entire fleet — from forwarders and indexers to search heads and deployment servers.


Pages in This Section

PageDescription
Getting Started with DAPProvisioning, enrollment tokens, and enrolling your first node
Platform PlanesShared DAP status, Splunk Enterprise worker plane, and product-scoped navigation
Splunk Execution CredentialsManagement credentials DAP workers use when executing approved plans
Pending ApprovalsReview and approve enrollment requests before hosts join the fleet
Inventory GroupsAssign enrolled hosts to Splunk roles with configuration-driven suggestions
API KeysCreate and manage Observer API keys for DAP integrations and AI agents
Insights NodesEnrolled hosts, operational state, and fleet visibility
Change PlansCreate, review, approve, and execute configuration changes
ExecutionsTrack plan execution history, live status, and per-job results
Insights DashboardFleet health, app inventory, certificate monitoring, and Splunk version distribution
Configuration BrowserSearch and inspect Splunk configurations across all enrolled nodes
Enterprise InventoryManage fleet topology, host groups, role assignments, and inventory templates

Overview

DAP connects to your Splunk hosts via lightweight Insights Nodes — agents that report operational state, configuration snapshots, and certificate status back to the platform. You manage everything from the Automation Platform section in the dashboard sidebar.

What You Can Do

  • Observe — See every enrolled Splunk host, its version, last check-in time, installed apps, and configuration details
  • Automate — Create change plans that bundle configuration changes, push them to nodes, and track execution
  • Govern — Approve or reject change plans before execution, review execution logs, and monitor rollout status
  • Monitor — Track fleet health with app coverage, certificate expiration alerts, and Splunk version distribution

How It Works

  1. Provision DAP — one-click provisioning from PlatformDAP Status connects your tenant to the Observer API
  2. Open a worker plane — use PlatformSplunk Enterprise for install snippets, enrollment, credentials, nodes, and inventory (see Platform Planes)
  3. Create enrollment tokens — generate Insights or Worker tokens to authenticate new hosts
  4. Enroll nodes — run the install command on each Splunk host (Insights add-on or Worker bootstrap)
  5. Approve enrollments — when policy requires it, review pending requests on Pending Approvals
  6. Assign inventory roles — map enrolled hosts to Splunk roles on Inventory Groups
  7. Create API keys — generate Observer API keys from PlatformAPI Keys
  8. Configure Splunk credentials — add management credentials workers use when executing approved plans (see Splunk Execution Credentials)
  9. Manage from the dashboard — use Observe and Automate to monitor fleet health, browse configs, create change plans, and track executions
  10. Self-repair — if connectivity degrades, use Reconnect Integration on DAP Status to restore the connection without losing data

Start with Getting Started with DAP to provision your tenant and enroll your first node.