Site Search

Does Splunk Need an Agent?

An agent-like program is not required.
Splunk can read and index log data in any format without the need for special adapters for IT data in a variety of formats. Splunk can get data from remote sources, such as syslog, SNMP, or by reading mirrored files via rsync or rotated files on a central log host via scp or ftp.
If your environment does not have a mechanism for remotely collecting data, you can use the Splunk Universal Forwarder. Even in this case, no development is required to match the format.