Enterprise Inventory

Manage fleet topology, host groups, role assignments, and inventory templates for DAP environments

Enterprise Inventory

Organize your Splunk fleet into logical groups, assign hosts to roles, and apply topology templates to standardize your DAP inventory structure across tenants and environments.


Overview

Enterprise Inventory gives you a structured view of your Splunk fleet organized by groups and roles. Instead of managing hosts individually, you define a topology — cluster peers, search heads, forwarders, deployment servers — and assign enrolled hosts to the appropriate role groups. This structure drives how DAP plans target hosts and how compliance baselines are evaluated.

You access Enterprise Inventory from the Enterprise section in the dashboard sidebar under Inventory.

Inventory Groups

Groups represent logical collections of hosts that share the same Splunk role. Each group maps to a DAP inventory role such as cluster_peer, forwarder, search_head_member, or deployment_server.

Viewing Groups

The Inventory page displays all groups in the current environment. Each group shows:

  • Display name — human-readable label
  • Role — the Splunk role this group represents
  • Member count — how many hosts are assigned
  • Parent group — the structural hierarchy (e.g., a cluster group)

Select a group from the list to see its member hosts with hostname, Splunk version, and last-seen timestamp.

Creating Groups

Click Create Group to add a new inventory group. Enter a group name — the system generates the appropriate internal name and maps it to a DAP role. Groups are scoped to the current tenant and environment.

Editing Groups

Use the Edit Groups dialog to manage which template-defined groups are active in your environment. Each row shows the group name, role, cluster assignment, and whether it has assigned hosts. Groups with assigned hosts or active child groups cannot be deactivated until their hosts are reassigned.

You can restore previously deactivated groups or deactivate groups you no longer need. Changes are saved as a batch — the system creates and removes groups in one operation.

Deleting Groups

Open the group's action menu and select Remove group. Removing a group does not delete the underlying DAP hosts — it only removes the group structure. Groups with assigned hosts must have their hosts reassigned first.

Assigning Hosts

Unassigned enrolled hosts appear in a separate pool. To assign a host to a group:

  1. Select a role-specific group (not a structural availability group).
  2. Click Add Host on the group.
  3. Select one or more unassigned hosts from the dialog.
  4. Confirm the assignment.

Each host receives a DAP inventory role and availability group based on the target group's position in the topology. Hosts assigned to a group appear in that group's member list with their hostname, Splunk version, and last check-in time.

Structural availability groups (labeled ag1, ag2, ag3) are rollup containers — you assign hosts to their child role groups, not directly to the availability group itself.

Inventory Templates

Templates define the complete topology structure for an environment — which groups exist, their hierarchy, role assignments, and cluster layout. Templates come from the DAP platform catalog and can be applied to any tenant environment.

Applying a Template

  1. Click Select Template on the Inventory page.
  2. Browse available catalog templates, organized by indexing tier (S, D, C, M).
  3. Review the template's role structure, including required and optional roles.
  4. Select which roles to activate using the role checklist (required roles are pre-selected and cannot be deactivated).
  5. Configure the topology selection — number of indexer clusters, search head clusters, and availability groups.
  6. Click Apply to create the group structure in your environment.

Applying a template creates all selected groups and sets up the parent-child hierarchy. You can then assign hosts to the leaf groups.

Template Details

Each template card shows:

  • Tier — the indexing tier (S = Single, D = Distributed, C = Clustered, M = Multi-cluster)
  • Description — what topology this template represents
  • Available roles — all roles defined in the template
  • Required roles — roles that cannot be deactivated
  • Role dependencies and conflicts — which roles depend on or conflict with each other

Managing Templates

The Templates tab provides a dedicated view for browsing, previewing, and managing templates. Enterprise admins with inventory:template:manage capability can:

  • Preview a template's full group structure before applying
  • Apply a template to the current tenant environment
  • Review which template is currently active via the Current Selection indicator

Multi-Tenant Support

If your organization has multiple tenants, use the tenant selector at the top of the Inventory page to switch between tenants. Each tenant has its own inventory environment with independent group structures and host assignments. The environment name is derived from the tenant name.

Permissions

ActionRequired Capability
View inventoryinventory:view or enterprise:manage
Create/edit/delete groupsinventory:manage or host:assign or enterprise:manage
Assign hostsinventory:manage or host:assign or enterprise:manage
Apply templatesinventory:template:manage or enterprise:manage

Audit Trail

All inventory mutations — group creation, host assignment, group deletion, template application — are recorded in the audit trail with the acting user, timestamp, and affected resource identifiers. View audit entries from the Enterprise Administration console.

Enterprise Inventory | Deslicer AI Docs