Comparison

DPLens vs Elastic Agent for collecting Windows logs.

Elastic Agent is built to feed the Elastic Stack. DPLens is a Windows agent that delivers to whichever SIEM or pipeline you run, Elastic included, with DPLens Manager for central management.

Last reviewed 1 October 2026

In short

Choose DPLens if your Windows events must reach Splunk, a syslog or Snare receiver, or an OpenTelemetry Collector, with or without Elastic. Elastic Agent needs another tier, such as Logstash, for Splunk or syslog; DPLens sends cooked S2S, HEC, syslog, Snare, NDJSON and OTLP/HTTP directly, masks sensitive data on the host, and is priced per agent and per network source with no per-GB charge. DPLens Manager, included in every subscription, gives you central configuration, fleet health monitoring, and deployment and upgrades, self-hosted and air-gap capable.

The DPLens case

Why teams choose DPLens over Elastic Agent

DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. Bracketed numbers refer to the sources at the foot of this page.

01

Splunk and Elastic in parallel, without a Logstash tier

Elastic Agent's outputs are Elasticsearch, Remote Elasticsearch, Logstash and Kafka [3][4]; its EDOT Collector adds OTLP, Kafka, file and load-balancing exporters, but no Splunk HEC or syslog exporter [17]. Logstash has syslog and HTTP outputs but no S2S [23]. DPLens delivers cooked S2S, HEC, syslog, Snare, NDJSON and OTLP/HTTP directly, to several destinations at once: Splunk and Elastic side by side while you migrate.

02

Central management, air-gap capable

Fleet-managed Elastic Agents depend on Fleet Server, and Fleet lives in Kibana [5]; in an air gap, Elastic documents self-hosting its package and artifact registries, or proxying to them [6]. DPLens Manager gives you central configuration, fleet health monitoring, and deployment and upgrades. It is self-hosted, air-gap capable and included in every subscription, and licensing works offline, with no telemetry and no licensing service.

03

Masking with built-in detectors

Card numbers, email, IP addresses, US SSN, UK NI and phone numbers, redacted, partially masked, tokenised or HMAC-hashed on the host, before anything is stored or sent. Elastic Agent can mask at the source too, with processors you write [11][12].

04

Cut per-GB bills with a fixed-price agent

If you pay per GB (Elastic Security Serverless starts from as low as $0.09 per GB ingested on its Essentials tier, plus retention [19]), filtering, aggregation and rate control on the host cut that bill. DPLens's own price is fixed per agent and network source: one syslog receiver for 500 firewalls is one seat. Try the savings calculator.

05

Specific answers for a security review

Secure by design: a tamper-evident audit trail, least privilege throughout, secrets protected on the machine, and Authenticode-signed releases with CycloneDX and SPDX SBOMs. Nothing calls home. See the Trust Centre.

Feature by feature

DPLens and Elastic Agent compared

Elastic entries come from Elastic's documentation, pricing and download pages and source repositories; DPLens entries from the DPLens documentation and DPLens Ltd.

DPLens compared with Elastic Agent and Fleet, as of 1 October 2026
CapabilityDPLensElastic Agent
Windows Event Log with XPathYes — any channel, including custom, with typed filters or your own XPath queryYes — Windows integrations and the Custom Windows Event Logs integration, filtered by channel, event ID, level and provider, or with a custom XML (XPath) query [7][15]
File tailingYes — path or wildcard, rotation followed, UTF-8 and UTF-16 detectedYes — Custom Logs (Filestream) integration [8]
Syslog and NetFlow receiversYes — syslog over UDP or TCP (RFC 3164 and 5424); NetFlow v5 and IPFIXYes — Custom UDP Logs and Custom TCP Logs (with TLS) parse RFC 3164 and 5424; NetFlow v1 to v9 and IPFIX [9][10][24]
Filtering and masking at the edgeYes — filter, aggregate, mask and rate-control stages; built-in detectors for card numbers, email, IP addresses, UK NI numbers and moreYes — agent processors run at the source, before ingest pipelines; the replace processor can mask PII [11][12]
Splunk output (S2S, HEC)Yes — cooked S2S (port 9997) to a pool of indexers, and HEC (port 8088)No — outputs are Elasticsearch, Remote Elasticsearch, Logstash and Kafka, and the EDOT Collector has no Splunk HEC exporter [3][4][17]
Syslog and Snare outputYes — syslog (RFC 5424 and 3164), Snare, NDJSON and raw relay, over UDP, TCP or TLSNo — not among the agent's outputs or EDOT exporters [3][4][17]; Logstash, a separate tier, has a syslog output [23]
OpenTelemetry (OTLP)Yes — OTLP over HTTP, to an OpenTelemetry Collector or any OTLP endpointYes — since 9.2 Elastic Agent embeds the EDOT Collector, Elastic's OpenTelemetry Collector distribution [16][17]
Delivery buffering and acknowledgementYes — disk-backed delivery per destination, every drop counted, optional Splunk indexer acknowledgementPartly — Elastic's output settings document an in-memory queue [13]; check your version for disk queueing. Elastic's reference architecture adds Logstash persistent queues for disk buffering [14]
Central fleet managementYes — DPLens Manager, includedYes — Fleet in Kibana, with Fleet Server as the control plane [5]
Licensing and costPriced per agent and per network source (each syslog or NetFlow receiver); no per-GB ingestion cost; works offlineThe default distribution is governed by the Elastic License; the agent's source is under Elastic License 2.0 [1][2]. Paid Elastic tiers are priced on resources, or per GB on Serverless [18][19]
Runs without a vendor cloud or call-homeYes — agents and DPLens Manager are self-hosted; no telemetry, no licensing service, no vendor control planeYes — Fleet Server can be self-managed; air-gapped use is documented with a self-hosted package registry and artifact registry [5][6]
Signed releases and SBOMYes — Authenticode SHA-256 signatures with RFC 3161 timestamps; CycloneDX and SPDX SBOMs with every releaseDownloads carry SHA-512 checksums and PGP (.asc) signatures, and the agent verifies PGP signatures on upgrade [2][6]; we found no published Elastic Agent SBOM as of 1 October 2026

Using both

DPLens on Windows, feeding Elastic

DPLens reaches Elastic over open protocols, alongside Splunk or another SIEM, so you can feed both from one agent.

OTLP to an EDOT Collector

Elastic documents an EDOT Collector gateway that receives OTLP on port 4318 and forwards to a self-managed Elastic Stack [20]. DPLens delivers logs there over OTLP/HTTP. See the OpenTelemetry integration.

NDJSON to Logstash

Logstash's tcp input supports TLS [21], and its json_lines codec decodes streamed newline-delimited JSON [22]. DPLens sends NDJSON over TLS with disk-backed delivery.

Syslog over TLS to Elastic Agent

Elastic's Custom TCP Logs integration parses RFC 3164 and 5424 and accepts TLS [24]. DPLens sends syslog over TLS with disk-backed delivery.

Deciding

DPLens is the right choice when

  • Your Windows events go to Splunk, a Snare receiver, a syslog SIEM or an OpenTelemetry pipeline, alone or alongside Elastic.
  • Your SIEM expects CIM or OCSF fields, normalised on the host.
  • You want central management on your own infrastructure, with no vendor control plane and nothing calling home.
  • Your security review asks for signed releases, SBOMs, a tamper-evident audit trail and least privilege.

Sources

Where the Elastic details come from

Last reviewed 1 October 2026. Elastic details are taken from Elastic's public documentation, pricing and download pages and source repositories on that date and may since have changed.

  • [1] elastic-agent LICENSE.txt — github.com
  • [2] Download Elastic Agent — elastic.co
  • [3] Configure outputs for standalone Elastic Agents — elastic.co
  • [4] Fleet settings (output types) — elastic.co
  • [5] What is Fleet Server? — elastic.co
  • [6] Run Elastic Agents in an air-gapped environment — elastic.co
  • [7] Custom Windows event log package — elastic.co
  • [8] Custom Logs (Filestream) package — elastic.co
  • [9] Custom UDP Logs integration — elastic.co
  • [10] NetFlow Records integration — elastic.co
  • [11] Elastic Agent processors — elastic.co
  • [12] Replace fields from events — elastic.co
  • [13] Elasticsearch output settings — elastic.co
  • [14] Elastic Agent to Logstash to Elasticsearch: Logstash persistent queue — elastic.co
  • [15] Custom Windows event log package manifest (xml_query option) — github.com
  • [16] Elastic Agent as an OpenTelemetry Collector — elastic.co
  • [17] EDOT Collector components — elastic.co
  • [18] Elastic pricing (Hosted, Serverless and self-managed) — elastic.co
  • [19] Elastic Security Serverless pricing — elastic.co
  • [20] Send data from an upstream OpenTelemetry Collector — elastic.co
  • [21] Logstash tcp input plugin — elastic.co
  • [22] Logstash json_lines codec plugin — elastic.co
  • [23] Logstash output plugins — elastic.co
  • [24] Custom TCP Logs integration — elastic.co

Elastic, Elasticsearch, Kibana, Logstash, Splunk, Snare and OpenTelemetry are trademarks of their respective owners. DPLens is not affiliated with or endorsed by them. Spotted something out of date? Tell us and we will correct it.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.