Insights Dashboard

Fleet health overview — node status, app coverage, certificate alerts, and Splunk version distribution

Insights Dashboard

The Insights Dashboard gives you a single-pane view of your Splunk fleet's health — node status, Splunk version distribution, cluster health, app coverage, and certificate expiration alerts.


Fleet Summary

Navigate to Automation PlatformInsights to see the fleet dashboard. The top-level cards show:

Node Status

MetricDescription
TotalAll enrolled nodes
OnlineNodes that checked in recently
StaleNodes that haven't checked in within the expected window
OfflineNodes that are unreachable

Splunk Version Distribution

A breakdown of Splunk Enterprise versions across your fleet, showing how many nodes run each version. Helps you identify hosts that need upgrades.

Cluster Health

MetricDescription
Clustered hostsTotal hosts in index or search head clusters
RF not metReplication factor violations
In maintenanceHosts in maintenance mode
Rolling restart activeClusters undergoing rolling restart
Bundle issuesKnowledge bundle replication problems
SHC not readySearch head cluster members not ready

Certificate Alerts

SeverityDescription
ExpiredCertificates past their expiration date
CriticalExpiring within 7 days
WarningExpiring within 30 days
AdvisoryExpiring within 90 days
HealthyValid certificates with no upcoming expiration

App Inventory

Navigate to InsightsApps to see a cross-fleet app inventory. The page has two tabs:

TabWhat It Shows
InventoryEvery distinct Splunk app across the fleet with coverage metrics
Compare hostsSide-by-side app presence for two or more selected hosts

Inventory Tab

For each Splunk app you see:

  • App name and configuration stanza count
  • Installed on — which hosts have the app
  • Missing from — which hosts do not
  • Coverage — percentage of enrolled hosts with the app installed
  • Last seen — when the app was last detected

Use the filter box to search by app name. Expand any app row to see the full list of hosts where it is installed or missing.

Compare Hosts Tab

Select at least two hosts from the picker to compare app inventories:

  • Shared apps — apps present on every selected host
  • Per-host deltas — apps installed on one host but missing from another

Use this view when validating deployment consistency across cluster peers, search head members, or forwarder tiers before approving a change plan.

Certificate Monitor

Navigate to InsightsCertificates to view all TLS certificates across your fleet. Filter by severity level and search by hostname, subject, or file path. Each certificate shows:

  • Host, file path, subject, and issuer
  • Validity dates and days remaining
  • Severity badge (Expired, Critical, Warning, Advisory, or Healthy)
  • Whether it is a default Splunk certificate or CA certificate

Inputs Coverage

Navigate to InsightsInputs Coverage to see every inputs.conf entry collected from Insights nodes across your fleet.

The page groups inputs by type (for example, monitor, tcp, udp, splunktcp). Each group shows:

  • Total stanza count and enabled vs. disabled breakdown
  • Apps and hosts where the input is defined
  • Config layer (local vs. deployed app) for each entry

Filter by host using the host selector. Click Refresh to reload coverage data from the Observer API. Coverage percentages count only Insights-origin hosts — worker-bootstrap hosts are excluded from the denominator because they do not collect input configuration.