Group details

The Groups list and group details pages show configuration, deployment, and collector information.

Summary cards

The Groups page provides search, filter, sort, and create actions. It also displays the following summary cards:

Card Description
Groups with processing issues Displays the number of groups experiencing errors or failures while processing telemetry data. A value greater than zero indicates that you should investigate collector health.
Groups with template update Displays the number of groups that have pending template changes. A configuration update is available or required to synchronize the group with the latest template version.
Groups list

Groups list columns

The following table describes the columns on the Groups list:

Column Description
Group name Displays the unique identifier for the group.
OS type Identifies the operating system associated with the group: Windows, Linux, or Kubernetes.
Collectors Displays the number of collectors that match the group after deployment. Collector counts are populated asynchronously after the group policy is deployed. Matching collectors receive the remote configuration and report status through OpAMP. Counts can take about a minute or longer to appear, depending on policy refresh and collector check-in timing.
Last edited Indicates the timestamp of the most recent configuration change.
Deployed by Lists the user who performed the last deployment.
Templates Displays the number of templates applied to the group.
Deployment status Displays whether the group is in Draft, Deployed, or Revised status.
  • Draft: The group has been created but has not been deployed yet. It does not actively manage any collectors.

  • Deployed: The group's latest saved configuration is active and manages matching collectors.

  • Revised: The group was deployed before, but it has saved changes that are not active yet. The currently deployed configuration continues to run until you deploy the revised version.

Collector status

Displays the aggregated remote configuration status for collectors that match the group.

  • Clear: All reporting collectors have successfully applied the deployed configuration, and the group has no reported collector configuration issues.

  • Issues: One or more collectors reported a problem receiving or applying the deployed configuration. Review the collector details to identify and resolve the issue.

Group summary fields

Select a group from the list to view its details. The summary section displays the following fields:

Field Description
Category Defines the host type or criteria used to filter the machines in the group, such as Windows Hosts.
Template Displays the template name used in the group and its Draft or Deployed status.
Count Indicates the total number of hosts identified as part of the group based on the applied criteria.

Collector detail fields

The following table describes collector information on the group details page:

Field Description
Host name Identifies the machine or instance.
Deployment status

Indicates whether the assigned configuration or template was applied to the host.

The status can be one of the following:

  • Applied: The collector has successfully received and applied the group configuration.

  • Applying: The collector has received the group configuration and is still applying it.

  • Mismatch: The reported configuration state of collector does not match the expected group configuration.

  • Failed: The collector attempted to apply the group configuration but failed.

Connection status Displays whether the host is communicating with Splunk Observability Cloud.
Distribution version Specifies the version of the software or agent running on the host.
Environment Categorizes the host by role or lifecycle stage, such as production, development, or staging.
OS type Identifies whether Windows, Linux, or Kubernetes runs on the host.
Template used Displays the configuration template that defines settings and monitoring parameters for the host.
Last status check Records the timestamp of the most recent heartbeat or health check received from the host.
Type Defines the entity classification, such as Agent, that indicates how data is collected.