Comparison
DPLens vs Cribl Edge for self-hosted Windows log collection.
Cribl Edge is part of a multi-product data pipeline suite and is priced on data ingested. DPLens is a signed Windows agent with no vendor control plane, priced per agent and per network source, with DPLens Manager included for central management.
In short
Choose DPLens if your estate is Windows and you want three things Cribl Edge does not give you: a cost fixed by agent and network-source count, not GB ingested; XPath filtering of each Windows Event Log channel on the host, without setting up Windows Event Forwarding; and file integrity monitoring and Snare output in the same agent. DPLens Manager, included in every subscription, gives you central configuration, fleet health monitoring, and deployment and upgrades, and DPLens can feed Cribl Stream or an OpenTelemetry Collector if you already run one.
The DPLens case
Why teams choose DPLens over Cribl Edge
DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. Bracketed numbers refer to the sources at the foot of this page.
01
A cost fixed at procurement
Cribl prices Edge on GB ingested [14]. Events dropped at the Edge or sent to DevNull do not count, and data Edge sends to Cribl Stream over Cribl HTTP or TCP is counted once [9][14]; what you keep is still metered. DPLens is priced per agent and per network source, so turning on Sysmon or verbose auditing does not change the bill, and one syslog receiver for 500 firewalls is one seat. Try the savings calculator or request an evaluation licence.
02
Windows filtering at the source
Cribl's local Windows Event Logs source has no event filter among its settings: you pick channels and filter in Pipelines [3]. DPLens filters each channel at the source by level, event ID and provider, or with your own XPath query, normalises to CIM or OCSF, and masks before anything is stored or sent. It also recommends what to collect, from a local scan of the machine's roles, services and audit policy.
03
FIM and Snare output in the same agent
Cribl lists no file integrity monitoring source and no Snare destination [2][6]. DPLens scans files, folders and wildcards against a baseline every 15 minutes, hourly or daily, without relying on object-access auditing (SACLs) on each path. It supports PCI DSS v4.0.1 11.5.2 change detection.
04
Central management included
Cribl manages Edge fleets from a Leader [1]. DPLens Manager gives you central configuration, fleet health monitoring, and deployment and upgrades for every DPLens agent, self-hosted and air-gap capable, and it is included in every subscription. The signed installer also deploys through Group Policy, Intune, Configuration Manager or an RMM; golden images and VDI are supported, and upgrades keep configuration and state.
05
Specific answers for a security review
Secure by design: a tamper-evident audit trail, least privilege throughout, secrets protected on the machine, and signed releases with CycloneDX and SPDX SBOMs. Nothing calls home, on any licence, where Cribl's Free licence requires telemetry [9]. See the Trust Centre.
Feature by feature
DPLens and Cribl Edge compared
Cribl entries come from Cribl's documentation and pricing pages; DPLens entries from the DPLens documentation and DPLens Ltd.
| Capability | DPLens | Cribl Edge |
|---|---|---|
| Windows Event Log filtered at the source | Yes — any channel, including custom; filtered at the source by level, event ID and provider, or with your own XPath query | Partly — the local Windows Event Logs source selects channels, with filtering in Pipelines after reading; XPath applies to WEF subscriptions received by the Windows Event Forwarder source [3][4] |
| File tailing | Yes — path or wildcard, rotation followed, UTF-8 and UTF-16 detected | Yes — File Monitor source [2] |
| File integrity monitoring | Yes — files, folders and wildcards, scanned every 15 minutes, hourly or daily | No — no file integrity monitoring source in the Edge Sources list [2] |
| Syslog and NetFlow receivers | Yes — syslog over UDP or TCP (RFC 3164 and 5424); NetFlow v5 and IPFIX | Yes — Syslog source [2], and a NetFlow & IPFIX source [12][13] |
| Filtering and masking at the edge | Yes — filter, aggregate, mask and rate-control stages; masking runs before anything is stored or sent | Yes — Drop, Sampling, Suppress, Aggregations and Mask functions, among many others [5] |
| Splunk output (S2S, HEC) | Yes — cooked S2S (port 9997) to a pool of indexers, and HEC (port 8088) | Yes — Splunk Single Instance and Splunk Load Balanced (S2S v3 or v4, data arrives cooked and parsed) and Splunk HEC [6][7] |
| Syslog, Snare and JSON output | Yes — syslog (RFC 5424 and 3164), Snare, NDJSON and raw relay, over UDP, TCP or TLS | Partly — Syslog, TCP JSON, Elasticsearch, Kafka, S3-compatible stores and many more; no Snare-format destination listed [6] |
| OpenTelemetry (OTLP) | Yes — OTLP over HTTP, to an OpenTelemetry Collector or any OTLP endpoint | Yes — OpenTelemetry source and destination [15][16] |
| Delivery buffering and acknowledgement | Yes — disk-backed delivery per destination, every drop counted, optional Splunk indexer acknowledgement | Yes — persistent queues on HTTP-based, load-balanced and single-receiver destinations, with Block, Drop or Queue backpressure; Cribl's Splunk Single Instance page says it does not enable full useACK behaviour [6][8][19] |
| Central fleet management | Yes — DPLens Manager, included | Yes — a Leader manages Edge fleets, in Cribl.Cloud or self-hosted (Cribl's on-premises Leader sizing covers up to 10,000 Edge Nodes); single-instance mode also available [1] |
| Pricing basis | Priced per agent and per network source (each syslog or NetFlow receiver); no per-GB ingestion cost; works offline | GB of data ingested: on-premises licences carry a daily ingest quota; events dropped at the Edge do not count; Cribl.Cloud is billed in Cribl Credits [9][10][14] |
| Runs without a vendor cloud or call-home | Yes — no telemetry, no licensing service, no vendor control plane | Partly — self-hosted and air-gapped licensing are documented; the Free licence must send telemetry to Cribl and blocks inbound traffic within 24 hours if it is disabled; paid licences can turn telemetry off [1][9] |
| Signed releases and SBOM | Yes — Authenticode SHA-256 signatures with RFC 3161 timestamps; CycloneDX and SPDX SBOMs with every release | Yes — an SBOM with every release; binaries, SBOMs and container images signed with Cosign [11] |
Using both
DPLens on Windows, feeding Cribl Stream or OpenTelemetry
DPLens filters and masks on the Windows host, so less data reaches the Cribl Stream or OpenTelemetry tier you already run, and less is metered there.
NDJSON to a TCP JSON source
Cribl Stream's TCP JSON source takes newline-delimited JSON; with no auth token set, its header line is optional [18]. DPLens sends NDJSON over TCP or TLS with disk-backed delivery; over TLS it validates the receiver's certificate by default.
OTLP to an OpenTelemetry source or Collector
Cribl Stream's OpenTelemetry source accepts OTLP/HTTP with binary protobuf on port 4318 once configured, though not on Cribl-managed Cloud Worker Groups [17]. DPLens can deliver there or to any OpenTelemetry Collector: see the OpenTelemetry integration.
Deciding
DPLens is the right choice when
- Your collection problem is Windows, and you want XPath filtering at the source, file integrity monitoring and Snare output from one agent.
- You want central configuration, fleet health and upgrades included in the subscription, self-hosted.
- You want a cost fixed by agents and network sources, not GB ingested.
- You operate air-gapped networks and want nothing that calls home, on any licence.
Check it yourself
In the documentation
- What a licence key covers
- Nothing calls home
- File integrity monitoring sources
- Sending NDJSON
- Golden images and VDI clones
Related: Windows Event Log collection, Splunk Universal Forwarder replacement, air-gapped log collection, OpenTelemetry, Trust Centre and all comparisons.
Sources
Where the Cribl details come from
- [1] Cribl Edge deployment planning — docs.cribl.io
- [2] Cribl Edge Sources — docs.cribl.io
- [3] Windows Event Logs Source — docs.cribl.io
- [4] Windows Event Forwarder Source — docs.cribl.io
- [5] Cribl Edge Functions — docs.cribl.io
- [6] Cribl Edge Destinations — docs.cribl.io
- [7] Splunk Load Balanced Destination — docs.cribl.io
- [8] Splunk Single Instance Destination — docs.cribl.io
- [9] Manage licences for Cribl on-prem deployments — docs.cribl.io
- [10] How does Cribl's cloud pricing work? — cribl.io
- [11] Software supply chain assurance at Cribl — cribl.io
- [12] NetFlow & IPFIX Source (Cribl Edge) — docs.cribl.io
- [13] Cribl Edge 4.10.0 release notes — docs.cribl.io
- [14] Cribl pricing ("Price based on GBs of data ingested") — cribl.io
- [15] OpenTelemetry Source (Cribl Edge) — docs.cribl.io
- [16] OpenTelemetry Destination (Cribl Edge) — docs.cribl.io
- [17] OpenTelemetry Source (Cribl Stream) — docs.cribl.io
- [18] TCP JSON Source (Cribl Stream) — docs.cribl.io
- [19] Persistent Queues (Cribl Edge) — docs.cribl.io
See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.