Unifying Your Data Strategy: Introducing Fully Supported Log Ingestion with the Splunk OpenTelemetry Collector

Platform Courtney Gannon

Key takeaways

  1. The Splunk OpenTelemetry Collector now provides a supported way to collect Linux and Windows host logs with a single, standardized approach.
  2. Using one OpenTelemetry based agent helps reduce agent sprawl, simplify management, and support open standards across environments.
  3. The Universal Forwarder remains the recommended option for technical add-ons, while the OpenTelemetry Collector is recommended for modern host log collection.

In today’s cloud-native landscape, OpenTelemetry (OTel) has become the industry standard for observability. Organizations are increasingly standardizing on OTel to ensure vendor neutrality, streamline their infrastructure, and gain deeper insights across their environments.

However, for many of our customers, a challenge has persisted. While Kubernetes and application tracing have embraced the OTel Collector, traditional Linux and Windows host log ingestion has remained a fragmented experience. Teams have often been forced to manage duplicate agents—the Universal Forwarder (UF) alongside the OTel Collector, implement the OpenTelemetry Collector as a TA, or rely on unsupported configurations to bridge the gap.

Today, we are excited to announce a fully supported, production-ready path for Linux and Windows host log ingestion via the Splunk OpenTelemetry Collector. With GA support for the Splunk OpenTelemetry Collector on Windows and Linux hosts, Splunk is helping customers take another step toward a simpler, more consistent data foundation for Cisco Data Fabric, powered by Splunk. By standardizing host telemetry collection through OpenTelemetry, teams can reduce agent sprawl, streamline deployment and management, and bring trusted operational data into Splunk for security, observability, and AI-ready use cases

Why This Matters

Our goal is to provide a unified data acquisition layer that works for you, regardless of your infrastructure. This new capability delivers:

When to Use OTel vs. The Universal Forwarder

We understand that security remains a top priority. To provide the best guidance for your specific needs:

For Observability & General Log Standardization: The Splunk OpenTelemetry Collector is now our recommended, supported path. It is designed to handle modern log ingestion needs efficiently, allowing you to filter, mask, and route data seamlessly.

For Technical Add-ons: The UF remains the solution to run technical add-ons that power additional Splunk solutions such as Enterprise Security or ITSI. This initiative is not about replacing the UF; it is about providing you with the right tool for the right job, ensuring that your observability pipelines are as modern and flexible as your applications.

What’s Included in the GA Release

We are rolling this out in two phases to ensure the highest level of support:

Linux Host Logs (GA Focus): Full documentation and support for OTel Collector configurations using filelog, syslog, journald, and hostmetrics receivers.

Windows Host Logs: Following the Linux release, we are bringing the same level of rigorous support to Windows-specific receivers, including windowseventlog, iis, and activedirectoryds receivers.

Moving Forward Together

This release is more than just a technical update, it is a commitment to the future of data management. By transforming raw, legacy host data into semantically structured, AI-ready information, we are helping you build a more agile and efficient data fabric.

We invite you to explore the documentation for the Splunk OpenTelemetry Collector and begin consolidating your host log ingestion today.

For more information on how to get started come talk to the Splunk OpenTelemetry experts at .conf26 in Denver in September.

Related Articles

Approaching Kubernetes Security — Detecting Kubernetes Scan with Splunk
Security
6 Minute Read

Approaching Kubernetes Security — Detecting Kubernetes Scan with Splunk

Approaching Kubernetes security. Detect and investigate Kubernetes cluster scan and fingerprinting using Splunk.
REvil Ransomware Threat Research Update and Detections
Security
8 Minute Read

REvil Ransomware Threat Research Update and Detections

On July 2, 2021, REvil group used Kaseya to distribute malware to its on-premises customers. Splunk has pushed out guidance to help understand and detect REvil. Learn more about the REvil ransomeware group, their tactics, and how to detect them using Splunk.
Threat Hunting for Dictionary-DGA with PEAK
Security
6 Minute Read

Threat Hunting for Dictionary-DGA with PEAK

Explore applied model-assisted threat hunting for dictionary-based domain generation algorithms using the SURGe Security Research Team's PEAK Threat Hunting Framework.