Comparison

DPLens vs Splunk Edge Processor: where should ingest be cut?

Splunk Edge Processor is a central processing tier that works alongside your forwarders: they send to it, and SPL2 pipelines filter, mask and route. DPLens does that work on the Windows machine itself, so sensitive data is masked before it reaches any other server. Many teams will want both.

Last reviewed 1 October 2026

In short

Choose DPLens for your Windows servers if card or personal data must be masked before it reaches any intermediate server, or if those servers sit across a WAN or branch link from where a processing tier would run. It filters and masks on the host, then delivers to Splunk over cooked S2S or HEC, to syslog SIEMs, Snare receivers or an OpenTelemetry Collector, with DPLens Manager, included in every subscription, for central configuration and fleet health. Where Edge Processor already serves your other sources, DPLens takes the Windows load off it and both feed the same indexes.

The case for DPLens

Why teams put DPLens on their Windows servers

DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. The Splunk licence saving from dropping an event is the same in either place; what differs is where the data has been by then. Numbers in brackets refer to the sources below.

01

Masked before it reaches any other server

Edge Processor masks in the tier [6], so unmasked card or personal data crosses the network to those servers and is processed there before it is masked. Systems that process or transmit that data can fall into audit scope, not only systems that store it. DPLens masks card numbers, email and IP addresses, phone numbers, UK NI and US social security numbers, and your own patterns, on the server, before anything is stored or sent.

02

What the UF cannot do, without a tier

The Universal Forwarder can include or exclude Windows events by Event ID or a regular expression on event fields [10], but cannot mask or reshape them; that needs a heavy forwarder [8] or a processing tier such as Edge Processor [5][6]. DPLens filters, aggregates, rate-limits and masks on the host itself.

03

Less traffic over the WAN

With Edge Processor, everything the forwarder does not exclude travels from each host to the tier before the rest of the noise is dropped [5]. That matters where Windows hosts sit across a WAN or branch link from the processing tier. Events DPLens drops never leave the machine.

04

No tier to run for Windows sources

Edge Processor runs on Linux hosts, containers or heavy forwarders that you size, patch and keep available [4][9]. For Windows sources DPLens needs none: each agent carries its own share of the work, with disk-backed delivery.

05

Destinations beyond Splunk

Edge Processor routes to Splunk, Amazon S3 and Azure storage [5][9]. DPLens also delivers to syslog SIEMs such as QRadar, Snare receivers, NDJSON collectors and, over OTLP/HTTP, an OpenTelemetry Collector, so changing SIEM is a destination change.

06

Nothing to check in with

Edge Processor instances contact the Edge Processor service for updates and telemetry [2][3]. DPLens has no vendor control plane, licensing works offline and nothing calls home, which matters most on air-gapped networks.

07

Central management included

DPLens Manager gives you central configuration, fleet health monitoring, and deployment and upgrades for every DPLens agent. It is self-hosted, air-gap capable and included in every subscription.

Using both

Cut Windows at the host, let Edge Processor handle the rest

You need not choose for the whole estate. Put DPLens on the Windows servers where masking or the network matters, and keep Edge Processor for network devices, Linux hosts and HEC clients.

  1. Pilot on your noisiest Windows servers

    Run DPLens beside the existing forwarder, delivering straight to your indexers with the same index and sourcetype, so searches do not change.

  2. Compare in Splunk

    Check counts Event ID by Event ID and run your saved searches. Edge Processor keeps handling every other source.

  3. Keep a rollback

    Disable the forwarder rather than removing it; restarting it restores the old path (details).

Feature by feature

DPLens and Splunk Edge Processor compared

Edge Processor entries come from Splunk's documentation; DPLens entries from the DPLens documentation and DPLens Ltd. An agent and a tier do different jobs, so some rows differ in kind.

DPLens compared with Splunk Edge Processor, as of 1 October 2026
CapabilityDPLensSplunk Edge Processor
Where it runsOn each Windows machine it collects from; Windows Server 2016–2025 and Windows 10/11, x64On Linux hosts (kernel 4.9 or later, x86 64-bit), single node or cluster [4]; in Docker or Kubernetes; and, since August 2026, on heavy forwarders in hybrid mode [9]
Windows Event Log collectionYes — any channel, including custom channels, filtered at the sourceNo — not an endpoint collector; it receives from forwarders, HEC clients, syslog devices [5] and Amazon Data Firehose [9]
File integrity monitoringYes — files, folders and wildcards, scanned every 15 minutes, hourly or dailyNo — not described as an Edge Processor function in the sources reviewed
Syslog and NetFlow receiversYes — syslog over UDP or TCP; NetFlow v5 and IPFIXPartly — receives syslog (RFC 3164, 5424 and 6587) [5]; NetFlow is not listed as a source
Filtering and maskingYes — on the host, before data is stored or sentYes — SPL2 pipelines filter, extract and mask in the tier [6]
How processing is definedStages in a fixed order (filter, parse, aggregate, optimise, enrich, mask, rate limit), set up in the console on the machine or centrally with DPLens ManagerSPL2 pipelines in a pipeline editor; regular expressions use PCRE2 syntax [6]
Output protocolsYes — cooked S2S, HEC, syslog, Snare, NDJSON and raw relayPartly — Splunk platform over S2S or HEC, Amazon S3, and Azure Blob Storage or Data Lake Storage [5][9]; syslog and Snare output are not listed
OpenTelemetry (OTLP) outputYes — OTLP over HTTP; detailsNot described in the sources reviewed [5][9]
Delivery bufferingYes — disk-backed delivery per destination, every drop counted, optional Splunk indexer acknowledgementYes — queued data stored on the host's disk as needed [4]; S2S acknowledgement in controlled availability since August 2026 [9]
Central managementYes — DPLens Manager, includedYes — instances and pipelines are managed from the Edge Processor service [2][3]
Licensing modelPer agent, plus a seat per syslog or NetFlow receiver; no per-GB cost; works offlineIncluded with Splunk Cloud Platform or Splunk Enterprise subscriptions; you provide the servers [1]
Telemetry and call-homeNone — no telemetry, no licensing service, no control planeThe supervisor contacts the service regularly for updates and to send telemetry, which excludes ingested data [2][3]

Splunk also offers Ingest Actions, which filter, mask and route on indexers, heavy forwarders and Splunk Cloud Platform [7], and Ingest Processor, a Splunk-hosted service that processes data after it reaches Splunk Cloud Platform [1].

Deciding

Put DPLens on your Windows servers when

  • Card or personal data must not reach an intermediate server unmasked.
  • Windows hosts sit across a WAN or branch link from your processing tier.
  • You send to more than Splunk, including an OpenTelemetry Collector, or may move away from it.
  • You would rather not size, patch and keep a processing tier available for Windows sources.

Sources

Where the Edge Processor details come from

Last reviewed 1 October 2026, from Splunk's public documentation and Splunk Lantern; details may since have changed.

  • [1] Getting started with Splunk Data Management Pipeline Builders (Splunk Lantern) — lantern.splunk.com
  • [2] System architecture of the Edge Processor solution (Splunk Cloud Platform) — help.splunk.com
  • [3] System architecture of the Edge Processor solution (Splunk Enterprise 10.2) — help.splunk.com
  • [4] Installation requirements for Edge Processors (Splunk Enterprise 10.2) — help.splunk.com
  • [5] How the Edge Processor solution transforms data — help.splunk.com
  • [6] Filter and mask data using an Edge Processor (Splunk Enterprise 10.4) — help.splunk.com
  • [7] Ingest actions requirements — help.splunk.com
  • [8] Types of forwarders (Splunk Enterprise 10.6) — help.splunk.com
  • [9] Release notes for Edge Processors (Splunk Cloud Platform), including Azure routing (29 June 2026), hybrid mode on heavy forwarders and S2S acknowledgement (10 August 2026), Docker and Kubernetes deployment, and Amazon Data Firehose input — help.splunk.com
  • [10] Monitor Windows event log data with Splunk Enterprise — help.splunk.com

Splunk, Splunk Edge Processor, SPL2 and other product names are trademarks of their respective owners. They are used here only to describe what DPLens interoperates with and is compared to. DPLens is not affiliated with or endorsed by Splunk. Tell us about anything out of date.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.