Comparison

DPLens vs the Snare agent: keep the Snare format, add Splunk, OpenTelemetry and masking.

DPLens emits Snare format, so your Snare receiver keeps its parser. From the same Windows agent you can also send cooked Splunk S2S, HEC, OTLP and NDJSON, and mask sensitive data before it leaves the host.

Last reviewed 1 October 2026

In short

Choose DPLens if your Snare estate is Windows and you want more from the same events. It writes the Snare format your receiver already parses, and from the same agent adds cooked Splunk S2S into your existing indexers, OpenTelemetry (OTLP over HTTP) and masking before anything leaves the host. DPLens Manager, included in every subscription, configures, monitors and upgrades the fleet centrally, and you can switch one server at a time without touching the receiver.

The case for switching

Why teams choose DPLens over Snare

DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. Numbers in brackets refer to the sources below.

01

Your receiver keeps its parser

DPLens writes Snare's tab-separated fields, or the same fields in an RFC 3164 line, over TCP, TLS or UDP, with certificate validation on by default and mutual TLS where the collector requires it. Nothing changes on the collector. Snare output

02

Cooked S2S into the indexers you already run

DPLens speaks the protocol Splunk forwarders use, so events land on your indexers' existing 9997 receiving port, spread across a pool of indexers with optional indexer acknowledgement, and with no HEC tokens to manage. Snare's agent page lists Splunk HEC, not the forwarder protocol [1]. HEC and OTLP too.

03

Masking before data leaves the host

Snare describes masking in Snare Reflector, its log routing engine [5], and its database activity monitoring product [4]; agent-side masking is not described in the sources reviewed. DPLens masks card numbers, email and IP addresses, UK NI numbers and your own patterns on the host, before anything is stored or sent.

04

Measured throughput

In our lab, DPLens delivered about 26,000–27,500 events a second on an 8-core Xeon E5-2430 v2 in Snare, S2S and NDJSON formats, at about 0.1 ms of CPU per event (lab figures, not a guarantee). Measure your current agent on the same server during a pilot. Method and caveats

05

Secure by design, and you can check it

Authenticode-signed releases with CycloneDX and SPDX SBOMs, a tamper-evident audit trail and least privilege throughout. The signatures and SBOMs let you check exactly what you install. See the Trust Centre.

06

Unmetered, offline licensing

DPLens is priced per agent and per network source (each syslog or NetFlow receiver), with no per-GB ingestion cost. Licensing works offline, with no licensing service or telemetry, so air-gapped is normal.

07

Central management included

DPLens Manager gives you central configuration, fleet health monitoring, and deployment and upgrades for every DPLens agent. It is self-hosted, air-gap capable and included in every subscription.

Low risk

Switching is low-risk

Because DPLens speaks Snare format, you can prove it against your own collector first.

  1. Point it at the same receiver

    Install DPLens beside the Snare agent and add a Snare destination that matches the existing agent's protocol, port and syslog-header setting. Use TLS where the collector supports it. DPLens can populate the message text and category column your collector expects.

  2. Run both and compare

    Compare what arrives from each; Live stream shows the exact record the collector receives. Keep the overlap short: the collector sees every event twice.

  3. Cut over, then add destinations

    Stop and remove the Snare agent. Add Splunk, OTLP or NDJSON destinations when you are ready, from the same agent.

Step by step: Snare agent replacement and replacing an existing Snare agent in the docs.

Feature by feature

DPLens and the Snare agent compared

Snare entries come from Snare's pages and v5 documentation; DPLens entries from the DPLens documentation and DPLens Ltd.

DPLens compared with the Snare agent (v5) and Snare Agent Manager, as of 1 October 2026
CapabilityDPLensSnare agent
Windows Event Log collection and filteringYes — any channel, including custom, with typed filters or your own XPath queryYes — include and exclude by event type, user or group, process, keyword and regular expression [1]
File tailingYes — path or wildcard, rotation followed, UTF-8 and UTF-16 detectedYes — "any text-based log file", with predefined formats such as IIS and DHCP logs [2]
Syslog and NetFlow receiversYes — syslog over UDP or TCP (RFC 3164 and 5424); NetFlow v5 and IPFIX, in the same agentPartly — Snare Central, a separate server, aggregates syslog and NetFlow [3]; a receiver in the Windows agent is not described in the sources reviewed
Filtering and masking at the edgeYes — filter, aggregate and rate-control stages; masking with built-in detectors and your own patternsPartly — filtering "is applied locally at the agent" [1]; masking is described in Snare Reflector [5] and Database Activity Monitoring [4], not in the agent
Splunk output (S2S, HEC)Yes — cooked S2S (port 9997) to a pool of indexers, and HEC (port 8088)Partly — Splunk HEC over HTTP or HTTPS [1]; the forwarder protocol (S2S) is not listed
OpenTelemetry (OTLP) outputYes — OTLP over HTTP, to an OpenTelemetry Collector or any OTLP endpointNot described in the sources reviewed
Snare and other outputsYes — Snare (tab-separated or RFC 3164), syslog (RFC 5424 and 3164), NDJSON and raw relay, over UDP, TCP or TLS; mutual TLS supportedYes — Snare native, syslog, JSON, CEF, LEEF and custom templates; Kafka, S3 and Microsoft Sentinel listed as targets; TLS 1.2 and 1.3, mutual TLS; up to 8 destinations [1]
Delivery bufferingYes — disk-backed delivery per destination, every drop counted, optional Splunk indexer acknowledgement; masking runs before anything is storedYes — "configurable encrypted local disk buffer", delivered in sequence on recovery [1]
Central managementYes — DPLens Manager, includedYes — Snare Agent Manager, included at no additional cost, with templates and air-gap-safe import and export [1]
Licensing modelPer agent and per network source; no per-GB cost; works offlinePricing on request [1]
Telemetry and call-homeNone — no telemetry, no licensing service, no control planeNot covered in the sources reviewed
Signed releases and SBOMYes — Authenticode SHA-256 with RFC 3161 timestamps; CycloneDX and SPDX SBOMsNot covered in the sources reviewed

Deciding

DPLens is the right choice when

  • Your Snare estate is Windows, and you want cooked Splunk S2S or OpenTelemetry alongside Snare format.
  • Personal or card data must be masked before it leaves the host.
  • You want licensing with no per-GB cost that works air-gapped.
  • Your vendor-risk review asks for signed releases, SBOMs and a tamper-evident audit trail.
  • You want central configuration and fleet health on your own infrastructure, included in the subscription.

Sources

Where the Snare details come from

Last reviewed 1 October 2026. Snare details are taken from Snare's public product pages and documentation on that date and may since have changed.

Snare, Snare Central and other product names are trademarks of their respective owners, used here only to describe what DPLens interoperates with and is compared to. DPLens is not affiliated with or endorsed by them. Spotted something out of date? Tell us and we will correct it.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.