Does Splunk need agents?
No. Splunk can process and index any format of log data without special adapters to interpret each format. It can access data remotely via syslog, SNMP, or by watching files mirrored via rsync or rotated to a central log host with scp or ftp. You can choose to deploy Splunk to access logfiles in real time on production hosts if you have datasources that don’t support remote logging, but this is the same Splunk software package and not a special agent.