Kentik has joined Infoblox! Read the blog post

Universal Agents

Prev Next

The Kentik Universal Agent collects availability, health, and performance telemetry from your network infrastructure. To extend the agent's functionality, install one or more Agent Capabilities on a host machine (see Universal Agent Deployment).

Did You Know?: All Kentik Agents will gradually be replaced with Agent Capabilities of the Kentik Universal Agent.

Agent Capabilities

Agent capabilities are the operational functions of an agent that allow it to perform tasks. Features of Kentik’s Universal Agent include:

  • Automatic self-updates

  • Sends host metrics and capability metrics to Data Explorer and Metrics Explorer

  • Support for alert creation based on agent and capability metric conditions

Supported Capabilities

The following table describes the different capabilities that Kentik Universal Agent supports, the methods to implement them, use cases, and related workflows.

For capability deployment and management through the portal, see Deploy a Universal Agent Through the Portal and Universal Agent Portal Management.

For capability deployment and management through the API, see Deploy a Universal Agent Through the Kentik API and Kentik's API Repo on GitHub. Kentik APIs provides an introduction to the Kentik API.

Capability

Description

Use Cases

Related Workflows

SNMP/ST

Discovers/collects NMS device data (SNMP or Streaming Telemetry).

Capability identifier: ranger

  • Monitor health and status of NMS devices.

  • Diagnose issues by analyzing device metrics.

  • Create alerts and notifications based on device metric threshold breaches and state changes.

SNMP Trap Receiver

Captures real-time events from SNMP-enabled devices.

Capability identifier:ksnmptrap

  • Filter and search trap events by name and OID.

  • Create alerts and notifications based on SNMP trap events.

  • Visualize trap events with other telemetry for quicker root cause analysis.

Syslog Server

Captures real-time log messages from devices

Capability identifier: ksyslog

  • Filter and search syslog events by name, severity, and message content.

  • Create alerts and notifications based on syslog events.

  • Visualize syslog events with other telemetry for quicker root cause analysis.

DNS OTT Tap

Provides deep visibility into DNS infrastructure by converting DNS queries into flow records, in addition to tapping into DNS data for OTT services.

Capability identifier:kdns

  • Detect and analyze “content events” for network operations guidance.

  • Evaluate OTT metrics for user categories and delivery methods (e.g., CDNs, interconnection types, or PoPs).

  • Assess Mbps-per-subscriber for OTT service impact.

  • Consider zero-rating content provider implications.

  • Improve customer retention by identifying delivery issues.

  • Analyze suspicious traffic for legal liability.

  • Get alerts on OTT service performance issues.

  • Identify flood attacks, reflection victims, and invalid queries.

  • Monitor response failures, record integrity, and performance baselines.

  • Validate expected values, audit TTLs, and monitor configuration changes in real-time.

Flow Proxy (Edge Processing)

Forwards network flow telemetry (e.g. NetFlow, sFlow, IPFIX) to the Kentik platform. Enriches the flow data on the agent.

Capability identifier: kproxy

  • Collecting flow in situations where  deploying a physical or virtual Kentik appliance is not feasible

  • Performance monitoring

  • Security monitoring and threat detection

  • Capacity planning & optimization

  • Decoding and processing is performed locally on a Kentik server.

Data Explorer

Flow Proxy (Forwarding)

Forwards flow data only to the Kentik platform, with no processing on the local platform.

Capability identifier: ktraffic

  • Decoding is performed on a SaaS cluster.

  • Recommended for high-volume flow collection when you want a low agent footprint and do not need on-premises decoding or enrichment.

Data Explorer

Connectivity Test

Enables on-demand IP connectivity testing via ping or traceroute.


Capability identifier: ksynth

  • Test for device connectivity, latency, or packet loss using ping .

  • Identify bottlenecks, points of failure, or routing loops using traceroute.

Synthetics

Notes:

  • A Universal Agent capability identifier matches its binary name. See Find the Capability Identifier for instructions.

  • The DNS OTT Tap capability replaces the standalone kprobe software agent as the method for tapping DNS data, as described in Enable OTT DNS Collection.

  • The Flow Proxy and SNMP/ST capabilities replace the standalone kproxy software agent as the method for forwarding flow telemetry data.

  • Some capabilities may be Early Access. Contact your Kentik Account Team for more information.

Find the Capability Identifier

The capabilities detail page, available through the Agent Details drawer, displays information about an installed capability, such as the Status, Version, Binary, and Run State.

To find the binary name (capability identifier) of a Universal Agent capability through the portal, follow these steps:

  1. Go to the Universal Agents page via Settings » Universal Agents in the Kentik portal's navbar.

  2. Under Agents, click an agent row. Clicking an agent row opens the Agent Details drawer.

  3. In the Agent Details drawer, click Installed Capabilities to display the capabilities paused or running on the agent.

  4. Click Details next to the capability you wish to view.

  5. In the capabilities detail page, find the Binary field. This field displays the binary name (capability identifier).

System Requirements

When deploying Universal Agents and enabling capabilities, ensure your host machine meets the necessary hardware requirements for optimal performance. Hardware needs scale based on the volume of telemetry data and the specific capabilities enabled. For details on running multiple capabilities simultaneously, see Understanding Agent Workload Scaling.

Capability / Agent

Recommended Hardware

Additional Notes

Flow Proxy (kproxy)

8 CPU cores, 32GB RAM

Recommended for 25,000+ FPS. Add a 20-30% buffer for bursty environments.

Flow Proxy (ktraffic)

1 CPU core, 2GB RAM

Recommended for 20,000+ FPS. (Note: Beta new flow proxy).

SNMP/ST

2 CPU cores, 8GB RAM

Recommended for environments with up to 500 Devices.

Syslog Server (ksyslog)

1 CPU core, 1GB RAM

Requirements scale based on log volume: Recommended for 8k events/sec.

Synthetics (Network & App)

2 CPU cores, 2GB RAM

Recommended for enterprise-scale, high-volume testing. Provides necessary headroom for burst test scenarios and multiple simultaneous synthetic tests.

BGP Proxy (Coming Soon)

2 CPU cores, 2GB RAM

Having extra capacity helps maintain stability during BGP table updates.

DNS OTT Tap

1 CPU core, 1GB RAM

Required for every 400k DNS lookups/sec.

Understanding Agent Workload Scaling

Running multiple capabilities with a single agent is a convenient deployment model. However, each additional capability compounds resource utilization, and workload contention can require significantly more CPU and memory to sustain equivalent performance.

Another common factor can be environmental and whether the traffic being ingested from sources such as Flow, syslog and traps occurs in bursty patterns or consistently over time. Highly volatile traffic patterns can require additional resources to properly scale the workload for reliability.

Supported Operating Systems

The Universal Agent is built and validated against the following distributions. Kentik utilizes modern toolchains that require specific library versions (e.g., glibc) found in these releases.

Support Matrix

The following table details the Linux distributions, supported operating system versions, and package formats validated for Universal Agent deployment.

Distribution

Supported Versions

Package Format

Debian

11 (Bullseye), 12 (Bookworm), 13 (Trixie)

.deb

Ubuntu

20.04 (Focal), 22.04 (Jammy), 24.04 (Noble)

.deb

Enterprise Linux (EL)

Oracle Linux 9, CentOS Stream 8

Legacy and Unsupported Systems

Kentik does not support the installation of the Universal Agent on distributions that have reached vendor End of Life (EOL).

  • CentOS 7: Officially unsupported. Internal capability workflows do not support building against CentOS 7 or any Enterprise Linux version prior to version 8.

  • Other EOL Distros: Any distribution version not explicitly listed in the Support Matrix is considered unsupported.

WARNING: Attempting to install the Universal Agent on unsupported systems will likely result in installation failures due to missing dependencies or runtime execution errors.

Agent Status

A deployed Universal Agent can be in one of the following states, as indicated in the Status column of the Universal Agents list:

  • Up: The agent was last seen by Kentik within 30 minutes.

  • Down: The agent was last seen by Kentik over 30 minutes ago.

  • Not Authorized: The agent is not yet authorized to connect to Kentik.

Note: Authorization is part of the agent installation process (see Universal Agent Deployment).

Network & Firewall Allowlist Requirements

This section details the network firewall requirements for the Universal Agent, including required outbound SaaS endpoints and local inbound ports.

Outbound SaaS Egress Rules

To ensure complete agent functionality and to prevent telemetry data loss, your perimeter firewalls must permit outbound egress traffic from the Universal Agent host to Kentik SaaS endpoints. All communication between the agent and Kentik SaaS is strictly outbound and encrypted using TLS over TCP port 443. Blocking required endpoints, such as api.kentik.com or grpc.api.kentik.com, can interrupt capability operations, software updates, and telemetry ingestion.

The Universal Agent strictly initiates all outbound connections to Kentik SaaS endpoints and encrypts all traffic using TLS 1.2 or higher over TCP port 443. At the application layer, the agent transmits data using standard HTTPS or HTTP/2-based gRPC. If your network uses Deep Packet Inspection (DPI) or SSL inspection proxies, your security policies must permit gRPC traffic over port 443.

The following table describes outbound rules from the agent host to Kentik SaaS.

Source

Destination (FQDN)

Protocol

Port

Required /

Optional

Capability / Description

Agent Host

flow.kentik.com

TCP

443

Required

Flow Proxy:
Transmits flow telemetry

Agent Host

grpc.api.kentik.com

TCP

443

Required

Control Plane & Telemetry:
Agent status, SNMP, Syslog, BGP Proxy

Agent Host

api.kentik.com

TCP

443

Required

Agent API and Synthetics:
DNS OTT Tap and Synthetics test data

Agent Host

portal.kentik.com

TCP

443

Required

Management: Registration and configuration sync

Agent Host

storage.googleapis.com

TCP

443

Required

Updates:
Capability binary downloads

Agent Host

whoami.kentiklabs.com

TCP

443

Optional

Diagnostics:
Public IP resolution

Agent Host

Configurable (Default: Flow Ingest)

UDP

40010

Optional

Flow Ingest Base Port: Direct UDP flow transport

Note: EU and EMEA tenants must replace *.kentik.com with *.kentik.eu endpoints.

Local Network Ingestion Rules

In addition to perimeter egress, internal network and host firewalls must allow local infrastructure to communicate directly with the Universal Agent host. The agent acts as a local receiver, using standard listening ports to capture telemetry (NetFlow / sFlow on UDP port 9995, SNMP polls on UDP port 161, and syslog server on UDP/TCP port 514). Certain capabilities may also require bi-directional or outbound local connections (SSH config scraping on TCP port 22, BGP peering sessions on TCP port 179) (see Agent Capabilities).

The following table describes the rules for internal network firewalls or host firewalls (iptables / ufw / Windows Firewall) allowing devices to communicate with the Universal Agent.

Traffic Direction

Source

Destination

Protocol

Port

Capability / Description

Inbound

Routers / Switches

Agent Host

UDP

9995

Flow Proxy: Receives NetFlow / sFlow / IPFIX

Bi-directional

Network Devices

Agent Host

UDP

161

SNMP/ST: SNMP polling requests and responses

Inbound

Network Devices

Agent Host

UDP

162

SNMP Trap Receiver: Listens for incoming SNMP traps

Inbound

Network Devices

Agent Host

UDP / TCP

514

Syslog Server: Captures device log messages

Inbound

Local NIC / Mirror

Agent Host

N/A

None

DNS OTT Tap: Passive packet capture via port mirror

Outbound

Agent Host

Managed Devices

TCP

22

Agentic Analysis: Scrapes SSH configuration

Bi-directional

Peer UA Agents

Agent Host

TCP / UDP

8877 / 9977

Synthetics: Agent-to-agent mesh testing

Inbound

eBGP Peers

Agent Host

TCP

179

BGP Proxy: BGP peering session