Comparison
DPLens vs Elastic Agent for collecting Windows logs.
Elastic Agent is built to feed the Elastic Stack. DPLens is a Windows agent that delivers to whichever SIEM or pipeline you run, Elastic included, with DPLens Manager for central management.
In short
Choose DPLens if your Windows events must reach Splunk, a syslog or Snare receiver, or an OpenTelemetry Collector, with or without Elastic. Elastic Agent needs another tier, such as Logstash, for Splunk or syslog; DPLens sends cooked S2S, HEC, syslog, Snare, NDJSON and OTLP/HTTP directly, masks sensitive data on the host, and is priced per agent and per network source with no per-GB charge. DPLens Manager, included in every subscription, gives you central configuration, fleet health monitoring, and deployment and upgrades, self-hosted and air-gap capable.
The DPLens case
Why teams choose DPLens over Elastic Agent
DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. Bracketed numbers refer to the sources at the foot of this page.
01
Splunk and Elastic in parallel, without a Logstash tier
Elastic Agent's outputs are Elasticsearch, Remote Elasticsearch, Logstash and Kafka [3][4]; its EDOT Collector adds OTLP, Kafka, file and load-balancing exporters, but no Splunk HEC or syslog exporter [17]. Logstash has syslog and HTTP outputs but no S2S [23]. DPLens delivers cooked S2S, HEC, syslog, Snare, NDJSON and OTLP/HTTP directly, to several destinations at once: Splunk and Elastic side by side while you migrate.
02
Central management, air-gap capable
Fleet-managed Elastic Agents depend on Fleet Server, and Fleet lives in Kibana [5]; in an air gap, Elastic documents self-hosting its package and artifact registries, or proxying to them [6]. DPLens Manager gives you central configuration, fleet health monitoring, and deployment and upgrades. It is self-hosted, air-gap capable and included in every subscription, and licensing works offline, with no telemetry and no licensing service.
03
Masking with built-in detectors
Card numbers, email, IP addresses, US SSN, UK NI and phone numbers, redacted, partially masked, tokenised or HMAC-hashed on the host, before anything is stored or sent. Elastic Agent can mask at the source too, with processors you write [11][12].
04
Cut per-GB bills with a fixed-price agent
If you pay per GB (Elastic Security Serverless starts from as low as $0.09 per GB ingested on its Essentials tier, plus retention [19]), filtering, aggregation and rate control on the host cut that bill. DPLens's own price is fixed per agent and network source: one syslog receiver for 500 firewalls is one seat. Try the savings calculator.
05
Specific answers for a security review
Secure by design: a tamper-evident audit trail, least privilege throughout, secrets protected on the machine, and Authenticode-signed releases with CycloneDX and SPDX SBOMs. Nothing calls home. See the Trust Centre.
Feature by feature
DPLens and Elastic Agent compared
Elastic entries come from Elastic's documentation, pricing and download pages and source repositories; DPLens entries from the DPLens documentation and DPLens Ltd.
| Capability | DPLens | Elastic Agent |
|---|---|---|
| Windows Event Log with XPath | Yes — any channel, including custom, with typed filters or your own XPath query | Yes — Windows integrations and the Custom Windows Event Logs integration, filtered by channel, event ID, level and provider, or with a custom XML (XPath) query [7][15] |
| File tailing | Yes — path or wildcard, rotation followed, UTF-8 and UTF-16 detected | Yes — Custom Logs (Filestream) integration [8] |
| Syslog and NetFlow receivers | Yes — syslog over UDP or TCP (RFC 3164 and 5424); NetFlow v5 and IPFIX | Yes — Custom UDP Logs and Custom TCP Logs (with TLS) parse RFC 3164 and 5424; NetFlow v1 to v9 and IPFIX [9][10][24] |
| Filtering and masking at the edge | Yes — filter, aggregate, mask and rate-control stages; built-in detectors for card numbers, email, IP addresses, UK NI numbers and more | Yes — agent processors run at the source, before ingest pipelines; the replace processor can mask PII [11][12] |
| Splunk output (S2S, HEC) | Yes — cooked S2S (port 9997) to a pool of indexers, and HEC (port 8088) | No — outputs are Elasticsearch, Remote Elasticsearch, Logstash and Kafka, and the EDOT Collector has no Splunk HEC exporter [3][4][17] |
| Syslog and Snare output | Yes — syslog (RFC 5424 and 3164), Snare, NDJSON and raw relay, over UDP, TCP or TLS | No — not among the agent's outputs or EDOT exporters [3][4][17]; Logstash, a separate tier, has a syslog output [23] |
| OpenTelemetry (OTLP) | Yes — OTLP over HTTP, to an OpenTelemetry Collector or any OTLP endpoint | Yes — since 9.2 Elastic Agent embeds the EDOT Collector, Elastic's OpenTelemetry Collector distribution [16][17] |
| Delivery buffering and acknowledgement | Yes — disk-backed delivery per destination, every drop counted, optional Splunk indexer acknowledgement | Partly — Elastic's output settings document an in-memory queue [13]; check your version for disk queueing. Elastic's reference architecture adds Logstash persistent queues for disk buffering [14] |
| Central fleet management | Yes — DPLens Manager, included | Yes — Fleet in Kibana, with Fleet Server as the control plane [5] |
| Licensing and cost | Priced per agent and per network source (each syslog or NetFlow receiver); no per-GB ingestion cost; works offline | The default distribution is governed by the Elastic License; the agent's source is under Elastic License 2.0 [1][2]. Paid Elastic tiers are priced on resources, or per GB on Serverless [18][19] |
| Runs without a vendor cloud or call-home | Yes — agents and DPLens Manager are self-hosted; no telemetry, no licensing service, no vendor control plane | Yes — Fleet Server can be self-managed; air-gapped use is documented with a self-hosted package registry and artifact registry [5][6] |
| Signed releases and SBOM | Yes — Authenticode SHA-256 signatures with RFC 3161 timestamps; CycloneDX and SPDX SBOMs with every release | Downloads carry SHA-512 checksums and PGP (.asc) signatures, and the agent verifies PGP signatures on upgrade [2][6]; we found no published Elastic Agent SBOM as of 1 October 2026 |
Using both
DPLens on Windows, feeding Elastic
DPLens reaches Elastic over open protocols, alongside Splunk or another SIEM, so you can feed both from one agent.
OTLP to an EDOT Collector
Elastic documents an EDOT Collector gateway that receives OTLP on port 4318 and forwards to a self-managed Elastic Stack [20]. DPLens delivers logs there over OTLP/HTTP. See the OpenTelemetry integration.
NDJSON to Logstash
Logstash's tcp input supports TLS [21], and its json_lines codec decodes streamed newline-delimited JSON [22]. DPLens sends NDJSON over TLS with disk-backed delivery.
Syslog over TLS to Elastic Agent
Elastic's Custom TCP Logs integration parses RFC 3164 and 5424 and accepts TLS [24]. DPLens sends syslog over TLS with disk-backed delivery.
Deciding
DPLens is the right choice when
- Your Windows events go to Splunk, a Snare receiver, a syslog SIEM or an OpenTelemetry pipeline, alone or alongside Elastic.
- Your SIEM expects CIM or OCSF fields, normalised on the host.
- You want central management on your own infrastructure, with no vendor control plane and nothing calling home.
- Your security review asks for signed releases, SBOMs, a tamper-evident audit trail and least privilege.
Check it yourself
In the documentation
Related: Windows Event Log collection, air-gapped log collection, OpenTelemetry, Trust Centre and all comparisons.
Sources
Where the Elastic details come from
- [1] elastic-agent LICENSE.txt — github.com
- [2] Download Elastic Agent — elastic.co
- [3] Configure outputs for standalone Elastic Agents — elastic.co
- [4] Fleet settings (output types) — elastic.co
- [5] What is Fleet Server? — elastic.co
- [6] Run Elastic Agents in an air-gapped environment — elastic.co
- [7] Custom Windows event log package — elastic.co
- [8] Custom Logs (Filestream) package — elastic.co
- [9] Custom UDP Logs integration — elastic.co
- [10] NetFlow Records integration — elastic.co
- [11] Elastic Agent processors — elastic.co
- [12] Replace fields from events — elastic.co
- [13] Elasticsearch output settings — elastic.co
- [14] Elastic Agent to Logstash to Elasticsearch: Logstash persistent queue — elastic.co
- [15] Custom Windows event log package manifest (
xml_queryoption) — github.com - [16] Elastic Agent as an OpenTelemetry Collector — elastic.co
- [17] EDOT Collector components — elastic.co
- [18] Elastic pricing (Hosted, Serverless and self-managed) — elastic.co
- [19] Elastic Security Serverless pricing — elastic.co
- [20] Send data from an upstream OpenTelemetry Collector — elastic.co
- [21] Logstash tcp input plugin — elastic.co
- [22] Logstash json_lines codec plugin — elastic.co
- [23] Logstash output plugins — elastic.co
- [24] Custom TCP Logs integration — elastic.co
See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.