Comparison

DPLens vs NXLog: which Windows log agent fits your estate?

NXLog Agent is a general-purpose, multi-platform collector. DPLens is built for one job, Windows log collection, with native Splunk delivery, masking built in, central management included and signed releases you can verify. Here is a dated, sourced comparison.

Last reviewed 1 October 2026

In short

Choose DPLens if your collection problem is Windows and your SIEM is Splunk or a syslog SIEM. It sends cooked Splunk S2S to your existing indexer inputs, masks sensitive data with built-in detectors rather than scripts, counts one licence seat per syslog receiver however many devices send to it, and ships as signed releases with SBOMs. DPLens Manager, included in every subscription, gives you central configuration, fleet health monitoring, and deployment and upgrades, self-hosted and air-gap capable.

The case for DPLens

Why teams choose DPLens over NXLog

DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. Here is what a Windows-focused team gains; numbers in brackets refer to the sources below.

01

Replace the Universal Forwarder without touching Splunk

Cooked S2S to your indexers' existing 9997 inputs, with index, host, source and sourcetype set per source, spread across a pool of indexers with optional indexer acknowledgement. No HEC tokens or HTTP load balancer to run. NXLog's Splunk guide uses HEC or raw TCP, UDP and TLS [4].

02

Cut ingest on the host, and see what you cut

Filter, aggregate and rate-control before delivery, and choose the wire format: in our lab an event was about 635 bytes as Snare and 1,377 as NDJSON. Every drop, mask and aggregation is counted against the rule that caused it.

03

Masking without writing code

Built-in detectors for card numbers, email, IP addresses, US SSNs, UK NI numbers and phone numbers, plus your own patterns, with redact, partial, token or HMAC actions, applied before anything is stored or sent. NXLog masks through regular-expression rewriting or the external Python script in its guide [3][10][13].

04

One seat per syslog receiver

200 firewalls through one receiver is one DPLens network source. Under NXLog's model each remote origin counts as a source, "even if their logs are forwarded through an intermediary" [14]. Neither charges per GB.

05

Secure by design, and you can check it

Authenticode-signed releases with CycloneDX and SPDX SBOMs, a tamper-evident audit trail and least privilege throughout. NXLog documents signed installers [9]; we found no SBOM published in the NXLog documentation we reviewed. See the Trust Centre.

06

Central management included

DPLens Manager gives you central configuration, fleet health monitoring, and deployment and upgrades for every DPLens agent. It is self-hosted, air-gap capable and included in every subscription, so fleet management is not an extra product to buy.

Performance: in our lab, DPLens delivered about 26,000–27,500 events a second on an 8-core Xeon E5-2430 v2 in Snare, S2S and NDJSON formats, at about 0.1 ms of CPU per event (lab figures, not a guarantee). Measure your current agent on the same server during a pilot. Method and caveats

Low risk

Switching is low-risk

If NXLog feeds Splunk, a syslog or Snare receiver, an NDJSON collector or an OTLP/HTTP endpoint, DPLens can deliver to the same receiver, so you can prove it on a few servers first.

  1. Install beside NXLog

    Install DPLens on a pilot group and add a destination for the same receiver.

  2. Run both and compare

    Compare counts and fields at the receiver; Live stream shows the exact record DPLens sends. Expect duplicates while both run, and check your searches and parsers see the fields they need.

  3. Cut over and roll out

    Stop NXLog on the pilot machines, then roll DPLens out with DPLens Manager, Group Policy or the management tool you already run.

See deployment options, Live stream and Windows Event Log collection.

Feature by feature

DPLens and NXLog Agent compared

NXLog entries come from NXLog's documentation and product pages. DPLens entries come from the DPLens documentation and DPLens Ltd.

DPLens compared with NXLog Agent and NXLog Platform, as of 1 October 2026
CapabilityDPLensNXLog
Windows Event Log with XPathYes — any channel, including custom, with typed filters or your own XPath queryYes — im_msvistalog with Query and QueryXML [1]
File tailingYes — path or wildcard, rotation followed, UTF-8 and UTF-16 detectedYes — im_file [2]
Syslog and NetFlow receiversYes — syslog over UDP or TCP (RFC 3164 and 5424); NetFlow v5 and IPFIX; one licence seat per receiverYes — UDP, TCP and TLS listeners with syslog parsing; NetFlow parser over UDP [2]; each sending device counts as a source [14]
Masking at the edgeYes — a mask stage with built-in detectors and redact, partial, token and HMAC actionsThrough regular-expression rewriting or external scripts [3][10][13]
Splunk outputYes — cooked S2S (port 9997) to a pool of indexers, and HEC (port 8088)Yes — over HEC, TCP, UDP and TLS; the Splunk guide does not offer cooked S2S [4]
OpenTelemetry (OTLP)Yes — OTLP over HTTP, to an OpenTelemetry Collector or any OTLP endpointYes — om_otel output and im_otel input [11][12]
Syslog, Snare and JSON outputYes — syslog (RFC 5424 and 3164), Snare, NDJSON and raw relay, over UDP, TCP or TLSYes — syslog, Snare format (to_syslog_snare) and JSON; HTTP(S) and batchcompress transports [2][5]
Delivery bufferingYes — disk-backed delivery per destination, every drop counted, optional Splunk indexer acknowledgementYes — persistent disk-backed queues; acknowledgement over HTTP(S) and batchcompress [6]
Central fleet managementYes — DPLens Manager, includedYes — NXLog Platform, up to 100,000 agents per node [7]
Licensing modelPer agent and per network source (syslog or NetFlow receiver); no per-GB ingestion cost; works offlinePer source, not data volume; each remote origin counts [14]
Self-hosted and air-gappedYes — agents and DPLens Manager are self-hosted and air-gap capable; no telemetry, no licensing service and no vendor control planeYes — NXLog Platform can be self-hosted on Linux or Kubernetes, with an air-gapped installer [7][8]
Signed releases and SBOMYes — Authenticode SHA-256 with RFC 3161 timestamps; CycloneDX and SPDX SBOMsSigned installers (Authenticode, PGP) [9]; no SBOM published in the docs we reviewed

Deciding

DPLens is the right choice when

  • Your collection problem is Windows, and you send to Splunk over cooked S2S, a Snare receiver or a syslog SIEM.
  • You want masking you configure, not code you maintain.
  • Many network devices send syslog, and you would rather license the receiver than each device.
  • You want central configuration and fleet health included in the subscription, on your own infrastructure.
  • Your vendor-risk review asks for signed releases, SBOMs, a tamper-evident audit trail and least privilege.

Sources

Where the NXLog details come from

Last reviewed 1 October 2026. NXLog details are taken from NXLog's public documentation and product pages on that date and may since have changed.

NXLog, Splunk, Snare and OpenTelemetry are trademarks of their respective owners. DPLens is not affiliated with or endorsed by them. Spotted something out of date? Tell us and we will correct it.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.