Splunk Enterprise

Splunk Dashboard for Certificate Expiry

raushank26
Loves-to-Learn

Hi All,

 

I am having a requirement to create a dashboard for fetching the expiry date of certificate used in Multiple Windows server.

There are load balancer used for these server. and also it cant be accessed by internet. means the app URL cannot be accessed from these server.

so is there any such utility in splunk or script through which we can create such dashboard.

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
Do you have any sample logs which show the expiry date of the certificates used?
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @raushank26 

You should check out the "SSL Certificate expiry collection" app on Splunkbase, ive used this before for monitoring the SSL cert of internal and external systems. Setup instructions are under the app on Splunkbase. This can be run on a Splunk Heavy Forwarder (HF) in a location where it can reach the target servers to conduct the checks.

Once setup you can create dashboard from the collected data, the fields collected by the add-on are:

  • date - date and time the input runs - now includes microseconds
  • fqdn - the hostname or FQDN hosting the certificate
  • inputstanza_name - the short name in input.conf after [fqdn_for_certificate://]
  • port - the port of the hostname or FQDN hosting the certificate
  • issuer - the organizationName in issuer
  • commonName - the commonName in issuer
  • use_proxy - if proxy was used
  • notAfter - date in notAfter from certificate
  • notBefore - date in netBefore from certificate
  • expiredays - the number of days until expiry
  • cipher - the name of the cipher being used
  • protocol - the version of the SSL protocol that defines its use
  • secret_bits - the number of secret bits being used

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

raushank26
Loves-to-Learn

Thanks for your response.

Just now i verified from the application server and i can see that the Splunk Universal Forwarder Service is running on all our servers but i cannot see Splunk Heavy Forwarder (HF).

Is there anything suggestion you have for Splunk Universal Forwarder Service so that my requirement for creating the dashboard get over.?

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...