Unifying Your Data Strategy: Introducing Fully Supported Log Ingestion with the Splunk OpenTelemetry Collector

Platform Courtney Gannon

Key takeaways

  1. The Splunk OpenTelemetry Collector now provides a supported way to collect Linux and Windows host logs with a single, standardized approach.
  2. Using one OpenTelemetry based agent helps reduce agent sprawl, simplify management, and support open standards across environments.
  3. The Universal Forwarder remains the recommended option for technical add-ons, while the OpenTelemetry Collector is recommended for modern host log collection.

In today’s cloud-native landscape, OpenTelemetry (OTel) has become the industry standard for observability. Organizations are increasingly standardizing on OTel to ensure vendor neutrality, streamline their infrastructure, and gain deeper insights across their environments.

However, for many of our customers, a challenge has persisted. While Kubernetes and application tracing have embraced the OTel Collector, traditional Linux and Windows host log ingestion has remained a fragmented experience. Teams have often been forced to manage duplicate agents—the Universal Forwarder (UF) alongside the OTel Collector, implement the OpenTelemetry Collector as a TA, or rely on unsupported configurations to bridge the gap.

Today, we are excited to announce a fully supported, production-ready path for Linux and Windows host log ingestion via the Splunk OpenTelemetry Collector. With GA support for the Splunk OpenTelemetry Collector on Windows and Linux hosts, Splunk is helping customers take another step toward a simpler, more consistent data foundation for Cisco Data Fabric, powered by Splunk. By standardizing host telemetry collection through OpenTelemetry, teams can reduce agent sprawl, streamline deployment and management, and bring trusted operational data into Splunk for security, observability, and AI-ready use cases

Why This Matters

Our goal is to provide a unified data acquisition layer that works for you, regardless of your infrastructure. This new capability delivers:

When to Use OTel vs. The Universal Forwarder

We understand that security remains a top priority. To provide the best guidance for your specific needs:

For Observability & General Log Standardization: The Splunk OpenTelemetry Collector is now our recommended, supported path. It is designed to handle modern log ingestion needs efficiently, allowing you to filter, mask, and route data seamlessly.

For Technical Add-ons: The UF remains the solution to run technical add-ons that power additional Splunk solutions such as Enterprise Security or ITSI. This initiative is not about replacing the UF; it is about providing you with the right tool for the right job, ensuring that your observability pipelines are as modern and flexible as your applications.

What’s Included in the GA Release

We are rolling this out in two phases to ensure the highest level of support:

Linux Host Logs (GA Focus): Full documentation and support for OTel Collector configurations using filelog, syslog, journald, and hostmetrics receivers.

Windows Host Logs: Following the Linux release, we are bringing the same level of rigorous support to Windows-specific receivers, including windowseventlog, iis, and activedirectoryds receivers.

Moving Forward Together

This release is more than just a technical update, it is a commitment to the future of data management. By transforming raw, legacy host data into semantically structured, AI-ready information, we are helping you build a more agile and efficient data fabric.

We invite you to explore the documentation for the Splunk OpenTelemetry Collector and begin consolidating your host log ingestion today.

For more information on how to get started come talk to the Splunk OpenTelemetry experts at .conf26 in Denver in September.

Related Articles

Explore the AI Frontier in Splunk’s State of Security 2024
Security
3 Minute Read

Explore the AI Frontier in Splunk’s State of Security 2024

Splunk's State of Security 2024: The Race to Harness AI report reveals the insights, aspirations, and challenges of security leaders.
Integrated Intelligence Enrichment With Threat Intelligence Management
Security
1 Minute Read

Integrated Intelligence Enrichment With Threat Intelligence Management

Threat Intelligence Management enables analysts to fully investigate security events or suspicious activity by providing the relevant and normalized intelligence to better understand threat context and accelerate time to triage.
Back from FiRST Berlin, discover CIRCL Passive SSL
Security
2 Minute Read

Back from FiRST Berlin, discover CIRCL Passive SSL