Comparison
DPLens vs the Snare agent: keep the Snare format, add Splunk, OpenTelemetry and masking.
DPLens emits Snare format, so your Snare receiver keeps its parser. From the same Windows agent you can also send cooked Splunk S2S, HEC, OTLP and NDJSON, and mask sensitive data before it leaves the host.
In short
Choose DPLens if your Snare estate is Windows and you want more from the same events. It writes the Snare format your receiver already parses, and from the same agent adds cooked Splunk S2S into your existing indexers, OpenTelemetry (OTLP over HTTP) and masking before anything leaves the host. DPLens Manager, included in every subscription, configures, monitors and upgrades the fleet centrally, and you can switch one server at a time without touching the receiver.
The case for switching
Why teams choose DPLens over Snare
DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. Numbers in brackets refer to the sources below.
01
Your receiver keeps its parser
DPLens writes Snare's tab-separated fields, or the same fields in an RFC 3164 line, over TCP, TLS or UDP, with certificate validation on by default and mutual TLS where the collector requires it. Nothing changes on the collector. Snare output
02
Cooked S2S into the indexers you already run
DPLens speaks the protocol Splunk forwarders use, so events land on your indexers' existing 9997 receiving port, spread across a pool of indexers with optional indexer acknowledgement, and with no HEC tokens to manage. Snare's agent page lists Splunk HEC, not the forwarder protocol [1]. HEC and OTLP too.
03
Masking before data leaves the host
Snare describes masking in Snare Reflector, its log routing engine [5], and its database activity monitoring product [4]; agent-side masking is not described in the sources reviewed. DPLens masks card numbers, email and IP addresses, UK NI numbers and your own patterns on the host, before anything is stored or sent.
04
Measured throughput
In our lab, DPLens delivered about 26,000–27,500 events a second on an 8-core Xeon E5-2430 v2 in Snare, S2S and NDJSON formats, at about 0.1 ms of CPU per event (lab figures, not a guarantee). Measure your current agent on the same server during a pilot. Method and caveats
05
Secure by design, and you can check it
Authenticode-signed releases with CycloneDX and SPDX SBOMs, a tamper-evident audit trail and least privilege throughout. The signatures and SBOMs let you check exactly what you install. See the Trust Centre.
06
Unmetered, offline licensing
DPLens is priced per agent and per network source (each syslog or NetFlow receiver), with no per-GB ingestion cost. Licensing works offline, with no licensing service or telemetry, so air-gapped is normal.
07
Central management included
DPLens Manager gives you central configuration, fleet health monitoring, and deployment and upgrades for every DPLens agent. It is self-hosted, air-gap capable and included in every subscription.
Low risk
Switching is low-risk
Because DPLens speaks Snare format, you can prove it against your own collector first.
Point it at the same receiver
Install DPLens beside the Snare agent and add a Snare destination that matches the existing agent's protocol, port and syslog-header setting. Use TLS where the collector supports it. DPLens can populate the message text and category column your collector expects.
Run both and compare
Compare what arrives from each; Live stream shows the exact record the collector receives. Keep the overlap short: the collector sees every event twice.
Cut over, then add destinations
Stop and remove the Snare agent. Add Splunk, OTLP or NDJSON destinations when you are ready, from the same agent.
Step by step: Snare agent replacement and replacing an existing Snare agent in the docs.
Feature by feature
DPLens and the Snare agent compared
Snare entries come from Snare's pages and v5 documentation; DPLens entries from the DPLens documentation and DPLens Ltd.
| Capability | DPLens | Snare agent |
|---|---|---|
| Windows Event Log collection and filtering | Yes — any channel, including custom, with typed filters or your own XPath query | Yes — include and exclude by event type, user or group, process, keyword and regular expression [1] |
| File tailing | Yes — path or wildcard, rotation followed, UTF-8 and UTF-16 detected | Yes — "any text-based log file", with predefined formats such as IIS and DHCP logs [2] |
| Syslog and NetFlow receivers | Yes — syslog over UDP or TCP (RFC 3164 and 5424); NetFlow v5 and IPFIX, in the same agent | Partly — Snare Central, a separate server, aggregates syslog and NetFlow [3]; a receiver in the Windows agent is not described in the sources reviewed |
| Filtering and masking at the edge | Yes — filter, aggregate and rate-control stages; masking with built-in detectors and your own patterns | Partly — filtering "is applied locally at the agent" [1]; masking is described in Snare Reflector [5] and Database Activity Monitoring [4], not in the agent |
| Splunk output (S2S, HEC) | Yes — cooked S2S (port 9997) to a pool of indexers, and HEC (port 8088) | Partly — Splunk HEC over HTTP or HTTPS [1]; the forwarder protocol (S2S) is not listed |
| OpenTelemetry (OTLP) output | Yes — OTLP over HTTP, to an OpenTelemetry Collector or any OTLP endpoint | Not described in the sources reviewed |
| Snare and other outputs | Yes — Snare (tab-separated or RFC 3164), syslog (RFC 5424 and 3164), NDJSON and raw relay, over UDP, TCP or TLS; mutual TLS supported | Yes — Snare native, syslog, JSON, CEF, LEEF and custom templates; Kafka, S3 and Microsoft Sentinel listed as targets; TLS 1.2 and 1.3, mutual TLS; up to 8 destinations [1] |
| Delivery buffering | Yes — disk-backed delivery per destination, every drop counted, optional Splunk indexer acknowledgement; masking runs before anything is stored | Yes — "configurable encrypted local disk buffer", delivered in sequence on recovery [1] |
| Central management | Yes — DPLens Manager, included | Yes — Snare Agent Manager, included at no additional cost, with templates and air-gap-safe import and export [1] |
| Licensing model | Per agent and per network source; no per-GB cost; works offline | Pricing on request [1] |
| Telemetry and call-home | None — no telemetry, no licensing service, no control plane | Not covered in the sources reviewed |
| Signed releases and SBOM | Yes — Authenticode SHA-256 with RFC 3161 timestamps; CycloneDX and SPDX SBOMs | Not covered in the sources reviewed |
Deciding
DPLens is the right choice when
- Your Snare estate is Windows, and you want cooked Splunk S2S or OpenTelemetry alongside Snare format.
- Personal or card data must be masked before it leaves the host.
- You want licensing with no per-GB cost that works air-gapped.
- Your vendor-risk review asks for signed releases, SBOMs and a tamper-evident audit trail.
- You want central configuration and fleet health on your own infrastructure, included in the subscription.
Check it yourself
In the documentation
- Sending Snare-format events
- Getting the Snare category column populated
- Replacing an existing Snare agent
- Sending to Splunk over cooked S2S or HEC
- Masking sensitive data
Related: Snare agent replacement, Splunk integration, OpenTelemetry integration, performance, licensing model, Trust Centre and all comparisons.
Sources
Where the Snare details come from
- [1] Snare Agents product page — snaresolutions.com
- [2] Log Files, Snare Windows Agent v5 documentation — prophecyinternational.atlassian.net
- [3] Snare Central product page — snaresolutions.com
- [4] Snare security solutions page — snaresolutions.com
- [5] Snare Reflector product page — snaresolutions.com
See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.