Unifying Your Data Strategy: Introducing Fully Supported Log Ingestion with the Splunk OpenTelemetry Collector
Platform Courtney GannonKey takeaways
- The Splunk OpenTelemetry Collector now provides a supported way to collect Linux and Windows host logs with a single, standardized approach.
- Using one OpenTelemetry based agent helps reduce agent sprawl, simplify management, and support open standards across environments.
- The Universal Forwarder remains the recommended option for technical add-ons, while the OpenTelemetry Collector is recommended for modern host log collection.
In today’s cloud-native landscape, OpenTelemetry (OTel) has become the industry standard for observability. Organizations are increasingly standardizing on OTel to ensure vendor neutrality, streamline their infrastructure, and gain deeper insights across their environments.
However, for many of our customers, a challenge has persisted. While Kubernetes and application tracing have embraced the OTel Collector, traditional Linux and Windows host log ingestion has remained a fragmented experience. Teams have often been forced to manage duplicate agents—the Universal Forwarder (UF) alongside the OTel Collector, implement the OpenTelemetry Collector as a TA, or rely on unsupported configurations to bridge the gap.
Today, we are excited to announce a fully supported, production-ready path for Linux and Windows host log ingestion via the Splunk OpenTelemetry Collector. With GA support for the Splunk OpenTelemetry Collector on Windows and Linux hosts, Splunk is helping customers take another step toward a simpler, more consistent data foundation for Cisco Data Fabric, powered by Splunk. By standardizing host telemetry collection through OpenTelemetry, teams can reduce agent sprawl, streamline deployment and management, and bring trusted operational data into Splunk for security, observability, and AI-ready use cases
Why This Matters
Our goal is to provide a unified data acquisition layer that works for you, regardless of your infrastructure. This new capability delivers:
-
A Unified Agent Strategy: Consolidate your observability and data collection. By using the Splunk OTel Collector for host logs, you can reduce resource overhead and simplify your deployment lifecycle.
-
Vendor Neutrality: Align with open-source standards. For organizations prioritizing interoperability, this path ensures you aren't locked into proprietary agents for standard host telemetry.
-
Operational Efficiency: Whether you are managing Linux environments or Windows servers, you can now use a consistent configuration pattern for log ingestion, including support for:
- Linux: /var/log/*, journald, audit logs, and syslog.
- Windows: Windows Event Log channels, IIS, and Active Directory Domain Services (AD DS).
When to Use OTel vs. The Universal Forwarder
We understand that security remains a top priority. To provide the best guidance for your specific needs:
For Observability & General Log Standardization: The Splunk OpenTelemetry Collector is now our recommended, supported path. It is designed to handle modern log ingestion needs efficiently, allowing you to filter, mask, and route data seamlessly.
For Technical Add-ons: The UF remains the solution to run technical add-ons that power additional Splunk solutions such as Enterprise Security or ITSI. This initiative is not about replacing the UF; it is about providing you with the right tool for the right job, ensuring that your observability pipelines are as modern and flexible as your applications.
What’s Included in the GA Release
We are rolling this out in two phases to ensure the highest level of support:
Linux Host Logs (GA Focus): Full documentation and support for OTel Collector configurations using filelog, syslog, journald, and hostmetrics receivers.
Windows Host Logs: Following the Linux release, we are bringing the same level of rigorous support to Windows-specific receivers, including windowseventlog, iis, and activedirectoryds receivers.
Moving Forward Together
This release is more than just a technical update, it is a commitment to the future of data management. By transforming raw, legacy host data into semantically structured, AI-ready information, we are helping you build a more agile and efficient data fabric.
We invite you to explore the documentation for the Splunk OpenTelemetry Collector and begin consolidating your host log ingestion today.
Related Articles

Approaching Kubernetes Security — Detecting Kubernetes Scan with Splunk

REvil Ransomware Threat Research Update and Detections
