Splunk Enterprise

Splunk Dashboard for Certificate Expiry

raushank26
Loves-to-Learn

Hi All,

 

I am having a requirement to create a dashboard for fetching the expiry date of certificate used in Multiple Windows server.

There are load balancer used for these server. and also it cant be accessed by internet. means the app URL cannot be accessed from these server.

so is there any such utility in splunk or script through which we can create such dashboard.

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
Do you have any sample logs which show the expiry date of the certificates used?
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @raushank26 

You should check out the "SSL Certificate expiry collection" app on Splunkbase, ive used this before for monitoring the SSL cert of internal and external systems. Setup instructions are under the app on Splunkbase. This can be run on a Splunk Heavy Forwarder (HF) in a location where it can reach the target servers to conduct the checks.

Once setup you can create dashboard from the collected data, the fields collected by the add-on are:

  • date - date and time the input runs - now includes microseconds
  • fqdn - the hostname or FQDN hosting the certificate
  • inputstanza_name - the short name in input.conf after [fqdn_for_certificate://]
  • port - the port of the hostname or FQDN hosting the certificate
  • issuer - the organizationName in issuer
  • commonName - the commonName in issuer
  • use_proxy - if proxy was used
  • notAfter - date in notAfter from certificate
  • notBefore - date in netBefore from certificate
  • expiredays - the number of days until expiry
  • cipher - the name of the cipher being used
  • protocol - the version of the SSL protocol that defines its use
  • secret_bits - the number of secret bits being used

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

raushank26
Loves-to-Learn

Thanks for your response.

Just now i verified from the application server and i can see that the Splunk Universal Forwarder Service is running on all our servers but i cannot see Splunk Heavy Forwarder (HF).

Is there anything suggestion you have for Splunk Universal Forwarder Service so that my requirement for creating the dashboard get over.?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...