What is the difference between agent-based and agentless checks, and what do you trade between them?
Agent-based means software installed on the monitored system collects data locally; agentless means the monitoring server queries from outside via SNMP, WMI, APIs or synthetic tests — depth versus deployment cost.
* Depth versus deployment: the agent sees inside and buffers, the agentless probe needs nothing installed but sees only what the protocol exposes. *
| Agent-based | Agentless | |
|---|---|---|
| How | Software runs on the target and collects locally | Queried remotely: SNMP, WMI, API calls, synthetic tests |
| Depth | High — processes, logs, per-application detail | Limited to what the protocol or API exposes |
| Works when the host is unreachable | Can buffer and resend | No — a network fault looks identical to a host fault |
| Cost | Install, patch and secure an agent everywhere | Nothing to deploy on the target |
| Typical use | Servers, containers, application stacks you own | Network gear, appliances, third-party and SaaS systems |
The decision is usually made for you: you cannot install an agent on a switch, a storage appliance or someone else's cloud service, so those are agentless by necessity. Where you can choose, the question is whether you need the detail an agent sees from inside — and whether you are willing to run one more piece of privileged software on every host.
Synthetic tests deserve a mention of their own: a robot that performs a real user journey (log in, search, check out) on a schedule. It is agentless, it measures the thing the business actually cares about, and it catches the "every component is green but the journey is broken" case that nothing else catches.
Go deeper:
Simple Network Management Protocol — Wikipedia — the classic agentless protocol: OIDs, polling and traps.
Prometheus — Exporters and integrations — the catalogue of agent-side exporters, one per system type.