Security data pipeline for Windows

Stop paying your SIEM to ingest noise.

DPLens is the self-hosted Windows log collection agent that replaces the Splunk Universal Forwarder and Snare. It filters, masks and routes events on the host, so only what matters reaches your SIEM. Signed, secure by design, and nothing calls home.

Engineer? Request an evaluation licence and test DPLens on your own host.

  • No per-GB costLicensed per agent and per network source, never by volume, so the data you send never changes your DPLens bill.How licensing works
  • Manager includedCentral configuration, fleet health monitoring, deployment and upgrades. Self-hosted and air-gap capable.About DPLens Manager
  • More than 30×the throughput of the established Windows agents we tested, at about a tenth of the CPU per event, in our lab benchmark.How we measured
  • 5 destination typesSplunk (S2S or HEC), syslog, Snare, NDJSON and OpenTelemetry (OTLP/HTTP), to several at once.See integrations

Where teams start

Start with the agent you run today.

Most teams begin by replacing a Splunk Universal Forwarder or Snare agent and cutting what reaches the SIEM. The same agent then takes on file integrity monitoring, masking of personal data and air-gapped collection.

Or start from the job

Pipeline stages

Every byte you don't send is a byte you don't pay for.

Every stage runs inside the agent, so noise dies on the endpoint instead of arriving in your SIEM with an invoice attached. Pick a stage to watch it work, then put a number on the saving with the calculator below.

Filter

Drop the events nobody has ever searched, before they cost anything. Keep or drop rules run in the agent, so the reduction lands on your licence rather than on a processing bill, and every drop is counted.

keep / drop rules filter by any field counted drops
Filter Filter drops events you never want to pay to store — 9.2M directory-object reads become none. ×
Action
Drop matching events Keep only matching
Conditions
Match All of the following ⌄
EventID is one of ⌄
4662 — Operation on a directory object ×
4663 — Attempt to access an object ×
e.g. 4662, 4663
×
Type a value and press Enter.
ProcessName is ⌄ e.g. Security ×
+ Add condition
Drop where EventID in 4662, 4663
Paste a sample event
Test with a sample
← Filter Cancel Add rule

What edge processing takes off the bill

Filtering, aggregation and routing happen before delivery, so reduction lands on your licence, not on a processing invoice. Move the sliders to your own figures: the defaults are illustrative assumptions, not a quote.

Daily volume collected800 GB/day
Reduced at the edge55%
Annual SIEM cost per GB/day of ingest£180 per GB/day / yr
Annual ingest avoided
£79k
Delivered to Splunk360 GB/day
Dropped or aggregated440 GB/day
Processing surchargeNone
Sources

Everything you need from your Windows servers, and the devices around them.

Security monitoring is only as good as its coverage. DPLens collects Windows Event Log, log files and file integrity on the host, and receives syslog and NetFlow from the firewalls, switches and appliances around it. Each source can then be filtered, masked and routed to where it's needed.

01

Windows Event Log

Security, System, Sysmon, PowerShell and any custom channel. Select exactly the events you need by Event ID, level, provider or your own XPath query, and collection picks up where it left off after a restart.

02

Log files

Follow any log file, path or wildcard through rotation and restarts, in UTF-8 or UTF-16. New files are picked up automatically.

03

File integrity monitoring

Scheduled change detection for files, folders and wildcards, scanned every 15 minutes, hourly or daily, with changes delivered as events. Supports PCI DSS v4.0.1 Requirement 11.5.2 (comparisons at least weekly) from the same agent that collects your logs.

04

Syslog

Receive RFC 3164 and RFC 5424 syslog over UDP or TCP from the firewalls, switches and appliances you allow. Each receiver counts as one network source for pricing, however many devices send to it.

05

NetFlow

Collect NetFlow v5 and IPFIX flow records from your network devices, then filter, aggregate or rate-limit them in the pipeline, so flow volume becomes a choice, not a bill.

06

Templates for common Windows roles

Start from a ready-made source for IIS, DNS, DHCP, SQL Server, Exchange or Windows security essentials, then tailor it to the machine.

SIEM integrations

Collect once. Send anywhere.

DPLens speaks Splunk natively, over cooked S2S as the Universal Forwarder does or through the HTTP Event Collector. It works with any SIEM that accepts syslog or JSON, including IBM QRadar, Securonix, Devo and Secureworks Taegis, and sends OTLP over HTTP to an OpenTelemetry Collector or any OTLP endpoint. Send to one destination or several at once, and add or switch destinations later with a configuration change, not a new agent rollout.

S2S & HEC supported natively no vendor lock-in TLS with certificate validation reduce noise and cost migrate without re-deploying

Moving SIEM? Send to the old and the new at the same time while you migrate.

Works with
DPLens
DPLens
collect filter · mask route
Splunk
Securonix
Devo
IBM QRadar
Secureworks Taegis
OpenTelemetry, syslog and NDJSON receivers

DPLens Manager

Run the whole fleet from one place.

DPLens Manager is included in every DPLens subscription.

Every DPLens subscription includes support 9am to 5pm UK time, Monday to Friday. Enhanced support is available as a paid option.

Central configuration

Manage the configuration of every DPLens agent centrally, rather than machine by machine.

Fleet health monitoring

Watch the health of every DPLens agent across your estate.

Deployment and upgrades

Deploy DPLens agents and keep them up to date across the fleet.

Self-hosted and air-gap capable

Runs on your infrastructure, including air-gapped networks, with no vendor cloud involved.

SECURITY BY DESIGN

Built to be checked, not trusted.

DPLens runs on the machines that matter most, with access to their logs. Signed releases, no call-home, least privilege and a tamper-evident record of every change let your security team verify it for themselves.

Signed, verifiable releases

Every full release is Authenticode-signed and published with SHA-256 checksums, so you can verify a package before it reaches a server.

SBOMs with every release

CycloneDX and SPDX software bills of materials ship with every release, ready for your software composition analysis and CVE triage.

Secure by design

Engineered for security from the first line of code, because an agent on your most important servers has to be.

Runs entirely on your infrastructure

Nothing calls home: no telemetry, no licensing service, no auto-update and no vendor control plane. Licence keys are verified offline, so an air-gapped machine is a normal deployment.

Tamper-evident audit trail

Sign-ins, configuration changes and rollbacks, and licence and masking-policy changes are recorded in an append-only audit trail, so any alteration is detectable.

Least privilege

DPLens holds only the rights it needs to collect and deliver your logs.

Compliance & regulation

Evidence, not assertions.

DPLens helps you evidence collection completeness, integrity monitoring, data minimisation and residency. Meeting each control remains your responsibility.

Framework
Requirement
How DPLens supports it
PCI DSS v4.0.1
10.2–10.5 audit logging and log integrity; 11.5.2 change detection
Disk-backed delivery with optional Splunk indexer acknowledgement, scheduled FIM (every 15 minutes, hourly or daily), a tamper-evident agent audit trail and PAN masking on the host
GDPR
Art. 5 minimisation; Art. 32 security of processing; transfer limits
Masking, keyed hashing and drop rules on the host, before anything is cached or sent; no vendor cloud, so processing stays where you run it
DORA / NIS2
ICT resilience, third-party concentration risk, incident reconstruction
Vendor-agnostic delivery to more than one SIEM at once, ordered failover, disk-backed buffering through outages, no vendor service needed to collect
HIPAA
§164.312 audit controls and integrity of ePHI
Masking rules redact or tokenise PHI on the host, with masking-policy changes in the audit log; TLS with certificate validation by default, and mutual TLS where the receiver requires it
ISO 27001 / SOC 2
A.8.15 logging, A.8.16 monitoring, change management evidence
Configuration as code, with every apply and rollback in the tamper-evident audit trail; central configuration and fleet health monitoring with DPLens Manager

See what DPLens would take off your SIEM bill.

Book a demo built around your own sources, SIEM and ingest figures, or request an evaluation licence and test DPLens on a Windows host of your own. Licensed per agent and per network source, with no per-GB ingestion cost.

Book a demo Request an evaluation licence

Prefer to talk first? Contact us.

Partner programme

We're looking for partners and resellers, worldwide.

Resellers, distributors, MSSPs, integrators and technology partners in every region. If your customers pay to ingest too much, DPLens is an easy addition to what you already sell.