Comparison
DPLens vs NXLog: which Windows log agent fits your estate?
NXLog Agent is a general-purpose, multi-platform collector. DPLens is built for one job, Windows log collection, with native Splunk delivery, masking built in, central management included and signed releases you can verify. Here is a dated, sourced comparison.
In short
Choose DPLens if your collection problem is Windows and your SIEM is Splunk or a syslog SIEM. It sends cooked Splunk S2S to your existing indexer inputs, masks sensitive data with built-in detectors rather than scripts, counts one licence seat per syslog receiver however many devices send to it, and ships as signed releases with SBOMs. DPLens Manager, included in every subscription, gives you central configuration, fleet health monitoring, and deployment and upgrades, self-hosted and air-gap capable.
The case for DPLens
Why teams choose DPLens over NXLog
DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. Here is what a Windows-focused team gains; numbers in brackets refer to the sources below.
01
Replace the Universal Forwarder without touching Splunk
Cooked S2S to your indexers' existing 9997 inputs, with index, host, source and sourcetype set per source, spread across a pool of indexers with optional indexer acknowledgement. No HEC tokens or HTTP load balancer to run. NXLog's Splunk guide uses HEC or raw TCP, UDP and TLS [4].
02
Cut ingest on the host, and see what you cut
Filter, aggregate and rate-control before delivery, and choose the wire format: in our lab an event was about 635 bytes as Snare and 1,377 as NDJSON. Every drop, mask and aggregation is counted against the rule that caused it.
03
Masking without writing code
Built-in detectors for card numbers, email, IP addresses, US SSNs, UK NI numbers and phone numbers, plus your own patterns, with redact, partial, token or HMAC actions, applied before anything is stored or sent. NXLog masks through regular-expression rewriting or the external Python script in its guide [3][10][13].
04
One seat per syslog receiver
200 firewalls through one receiver is one DPLens network source. Under NXLog's model each remote origin counts as a source, "even if their logs are forwarded through an intermediary" [14]. Neither charges per GB.
05
Secure by design, and you can check it
Authenticode-signed releases with CycloneDX and SPDX SBOMs, a tamper-evident audit trail and least privilege throughout. NXLog documents signed installers [9]; we found no SBOM published in the NXLog documentation we reviewed. See the Trust Centre.
06
Central management included
DPLens Manager gives you central configuration, fleet health monitoring, and deployment and upgrades for every DPLens agent. It is self-hosted, air-gap capable and included in every subscription, so fleet management is not an extra product to buy.
Performance: in our lab, DPLens delivered about 26,000–27,500 events a second on an 8-core Xeon E5-2430 v2 in Snare, S2S and NDJSON formats, at about 0.1 ms of CPU per event (lab figures, not a guarantee). Measure your current agent on the same server during a pilot. Method and caveats
Low risk
Switching is low-risk
If NXLog feeds Splunk, a syslog or Snare receiver, an NDJSON collector or an OTLP/HTTP endpoint, DPLens can deliver to the same receiver, so you can prove it on a few servers first.
Install beside NXLog
Install DPLens on a pilot group and add a destination for the same receiver.
Run both and compare
Compare counts and fields at the receiver; Live stream shows the exact record DPLens sends. Expect duplicates while both run, and check your searches and parsers see the fields they need.
Cut over and roll out
Stop NXLog on the pilot machines, then roll DPLens out with DPLens Manager, Group Policy or the management tool you already run.
See deployment options, Live stream and Windows Event Log collection.
Feature by feature
DPLens and NXLog Agent compared
NXLog entries come from NXLog's documentation and product pages. DPLens entries come from the DPLens documentation and DPLens Ltd.
| Capability | DPLens | NXLog |
|---|---|---|
| Windows Event Log with XPath | Yes — any channel, including custom, with typed filters or your own XPath query | Yes — im_msvistalog with Query and QueryXML [1] |
| File tailing | Yes — path or wildcard, rotation followed, UTF-8 and UTF-16 detected | Yes — im_file [2] |
| Syslog and NetFlow receivers | Yes — syslog over UDP or TCP (RFC 3164 and 5424); NetFlow v5 and IPFIX; one licence seat per receiver | Yes — UDP, TCP and TLS listeners with syslog parsing; NetFlow parser over UDP [2]; each sending device counts as a source [14] |
| Masking at the edge | Yes — a mask stage with built-in detectors and redact, partial, token and HMAC actions | Through regular-expression rewriting or external scripts [3][10][13] |
| Splunk output | Yes — cooked S2S (port 9997) to a pool of indexers, and HEC (port 8088) | Yes — over HEC, TCP, UDP and TLS; the Splunk guide does not offer cooked S2S [4] |
| OpenTelemetry (OTLP) | Yes — OTLP over HTTP, to an OpenTelemetry Collector or any OTLP endpoint | Yes — om_otel output and im_otel input [11][12] |
| Syslog, Snare and JSON output | Yes — syslog (RFC 5424 and 3164), Snare, NDJSON and raw relay, over UDP, TCP or TLS | Yes — syslog, Snare format (to_syslog_snare) and JSON; HTTP(S) and batchcompress transports [2][5] |
| Delivery buffering | Yes — disk-backed delivery per destination, every drop counted, optional Splunk indexer acknowledgement | Yes — persistent disk-backed queues; acknowledgement over HTTP(S) and batchcompress [6] |
| Central fleet management | Yes — DPLens Manager, included | Yes — NXLog Platform, up to 100,000 agents per node [7] |
| Licensing model | Per agent and per network source (syslog or NetFlow receiver); no per-GB ingestion cost; works offline | Per source, not data volume; each remote origin counts [14] |
| Self-hosted and air-gapped | Yes — agents and DPLens Manager are self-hosted and air-gap capable; no telemetry, no licensing service and no vendor control plane | Yes — NXLog Platform can be self-hosted on Linux or Kubernetes, with an air-gapped installer [7][8] |
| Signed releases and SBOM | Yes — Authenticode SHA-256 with RFC 3161 timestamps; CycloneDX and SPDX SBOMs | Signed installers (Authenticode, PGP) [9]; no SBOM published in the docs we reviewed |
Deciding
DPLens is the right choice when
- Your collection problem is Windows, and you send to Splunk over cooked S2S, a Snare receiver or a syslog SIEM.
- You want masking you configure, not code you maintain.
- Many network devices send syslog, and you would rather license the receiver than each device.
- You want central configuration and fleet health included in the subscription, on your own infrastructure.
- Your vendor-risk review asks for signed releases, SBOMs, a tamper-evident audit trail and least privilege.
Check it yourself
In the documentation
- Sending to Splunk over cooked S2S or HEC
- Masking sensitive data
- What a licence key covers, including receiver seats
- The tamper-evident audit trail
- Deployment options
- Supported operating systems
Related: Splunk Universal Forwarder replacement, log masking, OpenTelemetry integration, performance, licensing model, Trust Centre and all comparisons.
Sources
Where the NXLog details come from
- [1] Event Log for Windows (im_msvistalog) — docs.nxlog.co
- [2] NXLog Agent modules by type — docs.nxlog.co
- [3] Data masking — docs.nxlog.co
- [4] Send logs to Splunk — docs.nxlog.co
- [5] Snare integration — docs.nxlog.co
- [6] Reliable message delivery — docs.nxlog.co
- [7] NXLog Platform — nxlog.co
- [8] Install NXLog Platform on-premises — docs.nxlog.co
- [9] NXLog Agent digital signature — docs.nxlog.co
- [10] Rewriting and modifying logs — docs.nxlog.co
- [11] OpenTelemetry Exporter (om_otel) — docs.nxlog.co
- [12] OpenTelemetry Collector (im_otel) — docs.nxlog.co
- [13] Mask sensitive data with NXLog Agent — docs.nxlog.co
- [14] Data source-based licensing — nxlog.co
See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.