Where teams start
Start with the agent you run today.
Most teams begin by replacing a Splunk Universal Forwarder or Snare agent and cutting what reaches the SIEM. The same agent then takes on file integrity monitoring, masking of personal data and air-gapped collection.
Replace the UF
Splunk Universal Forwarder replacement
Deliver to your indexers over cooked S2S or HEC with the index and sourcetype your searches expect, and filter noisy events on the host before they count against your ingest licence.
Plan a UF replacementReplace Snare
Snare agent replacement
Send Snare-format records to the collector you already run, over TCP or TLS with disk-backed delivery, with filtering on the host to cut volume.
Plan a Snare replacementWeigh it up
Compare DPLens
Side-by-side, dated and sourced comparisons with the forwarders, agents and pipelines teams most often weigh up against DPLens.
See the comparisonsOr start from the job
Windows Event Log collection
Security, System, Sysmon and custom channels, filtered by Event ID at the source.
SIEM cost reduction
Filter, aggregate and rate-limit on the host, with every drop counted.
File integrity monitoring
Scheduled change detection that supports PCI DSS v4.0.1 Requirement 11.5.2.
PII masking and redaction
Mask card numbers, email addresses and UK National Insurance numbers before anything is cached or sent.
Air-gapped log collection
Offline signed licence keys, no telemetry and no licensing service.
All solutions
Every job DPLens does, on one page.
Every byte you don't send is a byte you don't pay for.
Every stage runs inside the agent, so noise dies on the endpoint instead of arriving in your SIEM with an invoice attached. Pick a stage to watch it work, then put a number on the saving with the calculator below.
Filter
Drop the events nobody has ever searched, before they cost anything. Keep or drop rules run in the agent, so the reduction lands on your licence rather than on a processing bill, and every drop is counted.
What edge processing takes off the bill
Filtering, aggregation and routing happen before delivery, so reduction lands on your licence, not on a processing invoice. Move the sliders to your own figures: the defaults are illustrative assumptions, not a quote.
Everything you need from your Windows servers, and the devices around them.
Security monitoring is only as good as its coverage. DPLens collects Windows Event Log, log files and file integrity on the host, and receives syslog and NetFlow from the firewalls, switches and appliances around it. Each source can then be filtered, masked and routed to where it's needed.
Windows Event Log
Security, System, Sysmon, PowerShell and any custom channel. Select exactly the events you need by Event ID, level, provider or your own XPath query, and collection picks up where it left off after a restart.
Log files
Follow any log file, path or wildcard through rotation and restarts, in UTF-8 or UTF-16. New files are picked up automatically.
File integrity monitoring
Scheduled change detection for files, folders and wildcards, scanned every 15 minutes, hourly or daily, with changes delivered as events. Supports PCI DSS v4.0.1 Requirement 11.5.2 (comparisons at least weekly) from the same agent that collects your logs.
Syslog
Receive RFC 3164 and RFC 5424 syslog over UDP or TCP from the firewalls, switches and appliances you allow. Each receiver counts as one network source for pricing, however many devices send to it.
NetFlow
Collect NetFlow v5 and IPFIX flow records from your network devices, then filter, aggregate or rate-limit them in the pipeline, so flow volume becomes a choice, not a bill.
Templates for common Windows roles
Start from a ready-made source for IIS, DNS, DHCP, SQL Server, Exchange or Windows security essentials, then tailor it to the machine.
Collect once. Send anywhere.
DPLens speaks Splunk natively, over cooked S2S as the Universal Forwarder does or through the HTTP Event Collector. It works with any SIEM that accepts syslog or JSON, including IBM QRadar, Securonix, Devo and Secureworks Taegis, and sends OTLP over HTTP to an OpenTelemetry Collector or any OTLP endpoint. Send to one destination or several at once, and add or switch destinations later with a configuration change, not a new agent rollout.
Moving SIEM? Send to the old and the new at the same time while you migrate.
DPLens Manager
Run the whole fleet from one place.
DPLens Manager is included in every DPLens subscription.
Every DPLens subscription includes support 9am to 5pm UK time, Monday to Friday. Enhanced support is available as a paid option.
Central configuration
Manage the configuration of every DPLens agent centrally, rather than machine by machine.
Fleet health monitoring
Watch the health of every DPLens agent across your estate.
Deployment and upgrades
Deploy DPLens agents and keep them up to date across the fleet.
Self-hosted and air-gap capable
Runs on your infrastructure, including air-gapped networks, with no vendor cloud involved.
Built to be checked, not trusted.
DPLens runs on the machines that matter most, with access to their logs. Signed releases, no call-home, least privilege and a tamper-evident record of every change let your security team verify it for themselves.
Signed, verifiable releases
Every full release is Authenticode-signed and published with SHA-256 checksums, so you can verify a package before it reaches a server.
SBOMs with every release
CycloneDX and SPDX software bills of materials ship with every release, ready for your software composition analysis and CVE triage.
Secure by design
Engineered for security from the first line of code, because an agent on your most important servers has to be.
Runs entirely on your infrastructure
Nothing calls home: no telemetry, no licensing service, no auto-update and no vendor control plane. Licence keys are verified offline, so an air-gapped machine is a normal deployment.
Tamper-evident audit trail
Sign-ins, configuration changes and rollbacks, and licence and masking-policy changes are recorded in an append-only audit trail, so any alteration is detectable.
Least privilege
DPLens holds only the rights it needs to collect and deliver your logs.
Evidence, not assertions.
DPLens helps you evidence collection completeness, integrity monitoring, data minimisation and residency. Meeting each control remains your responsibility.
See what DPLens would take off your SIEM bill.
Book a demo built around your own sources, SIEM and ingest figures, or request an evaluation licence and test DPLens on a Windows host of your own. Licensed per agent and per network source, with no per-GB ingestion cost.
We're looking for partners and resellers, worldwide.
Resellers, distributors, MSSPs, integrators and technology partners in every region. If your customers pay to ingest too much, DPLens is an easy addition to what you already sell.