Comparison
DPLens vs Splunk Edge Processor: where should ingest be cut?
Splunk Edge Processor is a central processing tier that works alongside your forwarders: they send to it, and SPL2 pipelines filter, mask and route. DPLens does that work on the Windows machine itself, so sensitive data is masked before it reaches any other server. Many teams will want both.
In short
Choose DPLens for your Windows servers if card or personal data must be masked before it reaches any intermediate server, or if those servers sit across a WAN or branch link from where a processing tier would run. It filters and masks on the host, then delivers to Splunk over cooked S2S or HEC, to syslog SIEMs, Snare receivers or an OpenTelemetry Collector, with DPLens Manager, included in every subscription, for central configuration and fleet health. Where Edge Processor already serves your other sources, DPLens takes the Windows load off it and both feed the same indexes.
The case for DPLens
Why teams put DPLens on their Windows servers
DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. The Splunk licence saving from dropping an event is the same in either place; what differs is where the data has been by then. Numbers in brackets refer to the sources below.
01
Masked before it reaches any other server
Edge Processor masks in the tier [6], so unmasked card or personal data crosses the network to those servers and is processed there before it is masked. Systems that process or transmit that data can fall into audit scope, not only systems that store it. DPLens masks card numbers, email and IP addresses, phone numbers, UK NI and US social security numbers, and your own patterns, on the server, before anything is stored or sent.
02
What the UF cannot do, without a tier
The Universal Forwarder can include or exclude Windows events by Event ID or a regular expression on event fields [10], but cannot mask or reshape them; that needs a heavy forwarder [8] or a processing tier such as Edge Processor [5][6]. DPLens filters, aggregates, rate-limits and masks on the host itself.
03
Less traffic over the WAN
With Edge Processor, everything the forwarder does not exclude travels from each host to the tier before the rest of the noise is dropped [5]. That matters where Windows hosts sit across a WAN or branch link from the processing tier. Events DPLens drops never leave the machine.
04
No tier to run for Windows sources
Edge Processor runs on Linux hosts, containers or heavy forwarders that you size, patch and keep available [4][9]. For Windows sources DPLens needs none: each agent carries its own share of the work, with disk-backed delivery.
05
Destinations beyond Splunk
Edge Processor routes to Splunk, Amazon S3 and Azure storage [5][9]. DPLens also delivers to syslog SIEMs such as QRadar, Snare receivers, NDJSON collectors and, over OTLP/HTTP, an OpenTelemetry Collector, so changing SIEM is a destination change.
06
Nothing to check in with
Edge Processor instances contact the Edge Processor service for updates and telemetry [2][3]. DPLens has no vendor control plane, licensing works offline and nothing calls home, which matters most on air-gapped networks.
07
Central management included
DPLens Manager gives you central configuration, fleet health monitoring, and deployment and upgrades for every DPLens agent. It is self-hosted, air-gap capable and included in every subscription.
Using both
Cut Windows at the host, let Edge Processor handle the rest
You need not choose for the whole estate. Put DPLens on the Windows servers where masking or the network matters, and keep Edge Processor for network devices, Linux hosts and HEC clients.
Pilot on your noisiest Windows servers
Run DPLens beside the existing forwarder, delivering straight to your indexers with the same index and sourcetype, so searches do not change.
Compare in Splunk
Check counts Event ID by Event ID and run your saved searches. Edge Processor keeps handling every other source.
Keep a rollback
Disable the forwarder rather than removing it; restarting it restores the old path (details).
Feature by feature
DPLens and Splunk Edge Processor compared
Edge Processor entries come from Splunk's documentation; DPLens entries from the DPLens documentation and DPLens Ltd. An agent and a tier do different jobs, so some rows differ in kind.
| Capability | DPLens | Splunk Edge Processor |
|---|---|---|
| Where it runs | On each Windows machine it collects from; Windows Server 2016–2025 and Windows 10/11, x64 | On Linux hosts (kernel 4.9 or later, x86 64-bit), single node or cluster [4]; in Docker or Kubernetes; and, since August 2026, on heavy forwarders in hybrid mode [9] |
| Windows Event Log collection | Yes — any channel, including custom channels, filtered at the source | No — not an endpoint collector; it receives from forwarders, HEC clients, syslog devices [5] and Amazon Data Firehose [9] |
| File integrity monitoring | Yes — files, folders and wildcards, scanned every 15 minutes, hourly or daily | No — not described as an Edge Processor function in the sources reviewed |
| Syslog and NetFlow receivers | Yes — syslog over UDP or TCP; NetFlow v5 and IPFIX | Partly — receives syslog (RFC 3164, 5424 and 6587) [5]; NetFlow is not listed as a source |
| Filtering and masking | Yes — on the host, before data is stored or sent | Yes — SPL2 pipelines filter, extract and mask in the tier [6] |
| How processing is defined | Stages in a fixed order (filter, parse, aggregate, optimise, enrich, mask, rate limit), set up in the console on the machine or centrally with DPLens Manager | SPL2 pipelines in a pipeline editor; regular expressions use PCRE2 syntax [6] |
| Output protocols | Yes — cooked S2S, HEC, syslog, Snare, NDJSON and raw relay | Partly — Splunk platform over S2S or HEC, Amazon S3, and Azure Blob Storage or Data Lake Storage [5][9]; syslog and Snare output are not listed |
| OpenTelemetry (OTLP) output | Yes — OTLP over HTTP; details | Not described in the sources reviewed [5][9] |
| Delivery buffering | Yes — disk-backed delivery per destination, every drop counted, optional Splunk indexer acknowledgement | Yes — queued data stored on the host's disk as needed [4]; S2S acknowledgement in controlled availability since August 2026 [9] |
| Central management | Yes — DPLens Manager, included | Yes — instances and pipelines are managed from the Edge Processor service [2][3] |
| Licensing model | Per agent, plus a seat per syslog or NetFlow receiver; no per-GB cost; works offline | Included with Splunk Cloud Platform or Splunk Enterprise subscriptions; you provide the servers [1] |
| Telemetry and call-home | None — no telemetry, no licensing service, no control plane | The supervisor contacts the service regularly for updates and to send telemetry, which excludes ingested data [2][3] |
Deciding
Put DPLens on your Windows servers when
- Card or personal data must not reach an intermediate server unmasked.
- Windows hosts sit across a WAN or branch link from your processing tier.
- You send to more than Splunk, including an OpenTelemetry Collector, or may move away from it.
- You would rather not size, patch and keep a processing tier available for Windows sources.
Check it yourself
In the documentation
- The pipeline stages, in order
- Keeping only what you care about
- Masking sensitive data
- Sending to Splunk over cooked S2S or HEC
- Nothing calls home
Related: log masking and PII redaction, SIEM cost reduction, Splunk integration, OpenTelemetry integration, DPLens vs the Splunk Universal Forwarder, savings calculator and all comparisons.
Sources
Where the Edge Processor details come from
- [1] Getting started with Splunk Data Management Pipeline Builders (Splunk Lantern) — lantern.splunk.com
- [2] System architecture of the Edge Processor solution (Splunk Cloud Platform) — help.splunk.com
- [3] System architecture of the Edge Processor solution (Splunk Enterprise 10.2) — help.splunk.com
- [4] Installation requirements for Edge Processors (Splunk Enterprise 10.2) — help.splunk.com
- [5] How the Edge Processor solution transforms data — help.splunk.com
- [6] Filter and mask data using an Edge Processor (Splunk Enterprise 10.4) — help.splunk.com
- [7] Ingest actions requirements — help.splunk.com
- [8] Types of forwarders (Splunk Enterprise 10.6) — help.splunk.com
- [9] Release notes for Edge Processors (Splunk Cloud Platform), including Azure routing (29 June 2026), hybrid mode on heavy forwarders and S2S acknowledgement (10 August 2026), Docker and Kubernetes deployment, and Amazon Data Firehose input — help.splunk.com
- [10] Monitor Windows event log data with Splunk Enterprise — help.splunk.com
See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.