Comparison

DPLens vs Cribl Edge for self-hosted Windows log collection.

Cribl Edge is part of a multi-product data pipeline suite and is priced on data ingested. DPLens is a signed Windows agent with no vendor control plane, priced per agent and per network source, with DPLens Manager included for central management.

Last reviewed 1 October 2026

In short

Choose DPLens if your estate is Windows and you want three things Cribl Edge does not give you: a cost fixed by agent and network-source count, not GB ingested; XPath filtering of each Windows Event Log channel on the host, without setting up Windows Event Forwarding; and file integrity monitoring and Snare output in the same agent. DPLens Manager, included in every subscription, gives you central configuration, fleet health monitoring, and deployment and upgrades, and DPLens can feed Cribl Stream or an OpenTelemetry Collector if you already run one.

The DPLens case

Why teams choose DPLens over Cribl Edge

DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. Bracketed numbers refer to the sources at the foot of this page.

01

A cost fixed at procurement

Cribl prices Edge on GB ingested [14]. Events dropped at the Edge or sent to DevNull do not count, and data Edge sends to Cribl Stream over Cribl HTTP or TCP is counted once [9][14]; what you keep is still metered. DPLens is priced per agent and per network source, so turning on Sysmon or verbose auditing does not change the bill, and one syslog receiver for 500 firewalls is one seat. Try the savings calculator or request an evaluation licence.

02

Windows filtering at the source

Cribl's local Windows Event Logs source has no event filter among its settings: you pick channels and filter in Pipelines [3]. DPLens filters each channel at the source by level, event ID and provider, or with your own XPath query, normalises to CIM or OCSF, and masks before anything is stored or sent. It also recommends what to collect, from a local scan of the machine's roles, services and audit policy.

03

FIM and Snare output in the same agent

Cribl lists no file integrity monitoring source and no Snare destination [2][6]. DPLens scans files, folders and wildcards against a baseline every 15 minutes, hourly or daily, without relying on object-access auditing (SACLs) on each path. It supports PCI DSS v4.0.1 11.5.2 change detection.

04

Central management included

Cribl manages Edge fleets from a Leader [1]. DPLens Manager gives you central configuration, fleet health monitoring, and deployment and upgrades for every DPLens agent, self-hosted and air-gap capable, and it is included in every subscription. The signed installer also deploys through Group Policy, Intune, Configuration Manager or an RMM; golden images and VDI are supported, and upgrades keep configuration and state.

05

Specific answers for a security review

Secure by design: a tamper-evident audit trail, least privilege throughout, secrets protected on the machine, and signed releases with CycloneDX and SPDX SBOMs. Nothing calls home, on any licence, where Cribl's Free licence requires telemetry [9]. See the Trust Centre.

Feature by feature

DPLens and Cribl Edge compared

Cribl entries come from Cribl's documentation and pricing pages; DPLens entries from the DPLens documentation and DPLens Ltd.

DPLens compared with Cribl Edge, as of 1 October 2026
CapabilityDPLensCribl Edge
Windows Event Log filtered at the sourceYes — any channel, including custom; filtered at the source by level, event ID and provider, or with your own XPath queryPartly — the local Windows Event Logs source selects channels, with filtering in Pipelines after reading; XPath applies to WEF subscriptions received by the Windows Event Forwarder source [3][4]
File tailingYes — path or wildcard, rotation followed, UTF-8 and UTF-16 detectedYes — File Monitor source [2]
File integrity monitoringYes — files, folders and wildcards, scanned every 15 minutes, hourly or dailyNo — no file integrity monitoring source in the Edge Sources list [2]
Syslog and NetFlow receiversYes — syslog over UDP or TCP (RFC 3164 and 5424); NetFlow v5 and IPFIXYes — Syslog source [2], and a NetFlow & IPFIX source [12][13]
Filtering and masking at the edgeYes — filter, aggregate, mask and rate-control stages; masking runs before anything is stored or sentYes — Drop, Sampling, Suppress, Aggregations and Mask functions, among many others [5]
Splunk output (S2S, HEC)Yes — cooked S2S (port 9997) to a pool of indexers, and HEC (port 8088)Yes — Splunk Single Instance and Splunk Load Balanced (S2S v3 or v4, data arrives cooked and parsed) and Splunk HEC [6][7]
Syslog, Snare and JSON outputYes — syslog (RFC 5424 and 3164), Snare, NDJSON and raw relay, over UDP, TCP or TLSPartly — Syslog, TCP JSON, Elasticsearch, Kafka, S3-compatible stores and many more; no Snare-format destination listed [6]
OpenTelemetry (OTLP)Yes — OTLP over HTTP, to an OpenTelemetry Collector or any OTLP endpointYes — OpenTelemetry source and destination [15][16]
Delivery buffering and acknowledgementYes — disk-backed delivery per destination, every drop counted, optional Splunk indexer acknowledgementYes — persistent queues on HTTP-based, load-balanced and single-receiver destinations, with Block, Drop or Queue backpressure; Cribl's Splunk Single Instance page says it does not enable full useACK behaviour [6][8][19]
Central fleet managementYes — DPLens Manager, includedYes — a Leader manages Edge fleets, in Cribl.Cloud or self-hosted (Cribl's on-premises Leader sizing covers up to 10,000 Edge Nodes); single-instance mode also available [1]
Pricing basisPriced per agent and per network source (each syslog or NetFlow receiver); no per-GB ingestion cost; works offlineGB of data ingested: on-premises licences carry a daily ingest quota; events dropped at the Edge do not count; Cribl.Cloud is billed in Cribl Credits [9][10][14]
Runs without a vendor cloud or call-homeYes — no telemetry, no licensing service, no vendor control planePartly — self-hosted and air-gapped licensing are documented; the Free licence must send telemetry to Cribl and blocks inbound traffic within 24 hours if it is disabled; paid licences can turn telemetry off [1][9]
Signed releases and SBOMYes — Authenticode SHA-256 signatures with RFC 3161 timestamps; CycloneDX and SPDX SBOMs with every releaseYes — an SBOM with every release; binaries, SBOMs and container images signed with Cosign [11]

Using both

DPLens on Windows, feeding Cribl Stream or OpenTelemetry

DPLens filters and masks on the Windows host, so less data reaches the Cribl Stream or OpenTelemetry tier you already run, and less is metered there.

NDJSON to a TCP JSON source

Cribl Stream's TCP JSON source takes newline-delimited JSON; with no auth token set, its header line is optional [18]. DPLens sends NDJSON over TCP or TLS with disk-backed delivery; over TLS it validates the receiver's certificate by default.

OTLP to an OpenTelemetry source or Collector

Cribl Stream's OpenTelemetry source accepts OTLP/HTTP with binary protobuf on port 4318 once configured, though not on Cribl-managed Cloud Worker Groups [17]. DPLens can deliver there or to any OpenTelemetry Collector: see the OpenTelemetry integration.

Deciding

DPLens is the right choice when

  • Your collection problem is Windows, and you want XPath filtering at the source, file integrity monitoring and Snare output from one agent.
  • You want central configuration, fleet health and upgrades included in the subscription, self-hosted.
  • You want a cost fixed by agents and network sources, not GB ingested.
  • You operate air-gapped networks and want nothing that calls home, on any licence.

Sources

Where the Cribl details come from

Last reviewed 1 October 2026. Cribl details are taken from Cribl's public documentation and product pages on that date and may since have changed.

Cribl, Cribl Edge, Cribl Stream, Splunk, Snare and OpenTelemetry are trademarks of their respective owners. DPLens is not affiliated with or endorsed by them. Spotted something out of date? Tell us and we will correct it.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.