Comparison

DPLens vs the Splunk Universal Forwarder on Windows.

The Universal Forwarder sends Windows events into Splunk as they are, to be metered at the indexer. DPLens filters and masks them on the host first, keeps your index and sourcetype, and can add a non-Splunk destination at the same time.

Last reviewed 1 October 2026

In short

Choose DPLens if Windows event volume drives your Splunk licence or personal data must not leave the server unmasked. It filters and masks events on the host before Splunk meters them, delivers over cooked S2S or HEC with your existing index and sourcetype, and can feed a syslog SIEM or an OpenTelemetry Collector at the same time. DPLens Manager, included in every subscription, configures, monitors and upgrades the fleet centrally, and you can run DPLens alongside the Universal Forwarder (UF) until the data proves itself.

The case for DPLens

Why teams choose DPLens over the Universal Forwarder

DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. Numbers in brackets refer to the sources below.

01

Reduce where the events are created

On ingest-based licences, Splunk meters data when it is indexed [2]. The UF can allow or deny events by event code or a regular expression on event fields, and drop message text [3]; further filtering is a heavy forwarder feature [1]. Ingest Actions [13] and Edge Processor also drop data before it is metered, but on a tier after the full stream has crossed your network. DPLens adds field conditions, collapsed repeats and per-machine rate caps on the host, counting every removal against its rule. Size it with the savings calculator.

02

Mask before it leaves the server

Splunk documents anonymisation on a heavy forwarder or indexer [6]; Ingest Actions run on indexers, heavy forwarders and Splunk Cloud Platform [13]. DPLens masks card numbers, email and IP addresses, phone numbers, UK NI and US social security numbers, and your own patterns, on the server, before anything is stored or sent.

03

Keep your index and sourcetype

Cooked S2S on 9997 to a pool of indexers, or HEC on 8088, with index, host, source and sourcetype set per source. Events arrive in the familiar flattened Windows format or as the raw event XML, so your searches and dashboards keep working; confirm it side by side in the parallel run.

04

Measured on a busy channel

In our lab, DPLens delivered about 26,000–27,500 events per second on an 8-core Xeon E5-2430 v2 (Snare, S2S and NDJSON formats), at about 0.1 ms of CPU per event (method and caveats; lab figures, not a guarantee). Measure your current agent on the same server during your parallel run.

05

A non-Splunk destination alongside Splunk

A UF can forward raw TCP to a third party, but cannot route it per event and has no syslog output [8]. One DPLens pipeline feeds several destinations at once: Splunk plus syslog over TLS, Snare, NDJSON or OTLP to an OpenTelemetry Collector, for a SIEM migration or a second copy.

06

Central management included

DPLens Manager gives you central configuration, fleet health monitoring, and deployment and upgrades for every agent. It is self-hosted, air-gap capable and included in every subscription.

07

FIM included, no per-GB price

Scheduled file integrity monitoring runs in the same agent and licence. DPLens is priced per agent, plus a seat per syslog or NetFlow receiver (never per sending device). Licensing works offline and nothing calls home.

08

Secure by design

Signed releases with CycloneDX and SPDX SBOMs, a tamper-evident audit trail, least privilege and no telemetry. See the Trust Centre.

Splunk's own OpenTelemetry route

In July 2026 Splunk announced generally available log ingestion with its OpenTelemetry Collector, starting with Linux; it says Windows receivers, including windowseventlog, follow [14]. DPLens is Windows-native today, and delivers OTLP over HTTP to that Collector.

Low-risk change

Switching is low-risk

The UF stays until the data proves itself. The migration guide maps your Universal Forwarder inputs and outputs line by line.

  1. Run alongside

    Install DPLens next to the UF, sending to the same indexers, index and sourcetype. Keep the overlap short: on ingest-based licences both copies count against your licence.

  2. Compare in Splunk

    Search both, Event ID by Event ID, and run your saved searches. Every difference should be one your filters explain.

  3. Cut over by server group, with a rollback

    Disable the UF rather than uninstalling it. To roll back, start it again: it resumes from its own checkpoint (details).

At scale

Running it across thousands of servers

  • Central management: DPLens Manager, included in every subscription, gives you central configuration, fleet health monitoring, and deployment and upgrades. It is self-hosted and air-gap capable.
  • Install your way: the signed installer also deploys through Group Policy, Intune, Configuration Manager or an RMM.
  • Images and VDI: golden images and VDI are supported deployment methods, and generalised clones start with fresh state.
  • Upgrades: in place, keeping configuration, licence, secrets, collection positions and cache.
  • Health: watch the fleet in DPLens Manager, and alert in Splunk on hosts that stop sending and on the signals the documentation lists.
  • Support: every subscription includes support 9am to 5pm UK time, Monday to Friday, and enhanced support is available as a paid option (support and lifecycle).

Feature by feature

DPLens and the Universal Forwarder compared

UF entries come from Splunk's documentation; DPLens entries from the DPLens documentation and DPLens Ltd.

DPLens compared with the Splunk Universal Forwarder, as of 1 October 2026
CapabilityDPLensSplunk Universal Forwarder
Windows Event Log filteringYes — any channel, with field conditions, aggregation and rate caps on the hostYes — allow and deny lists by event code, or key and regular expression; message text can be dropped [3]
File integrity monitoringYes — files, folders and wildcards, scanned every 15 minutes, hourly or dailyPartly — through object-access auditing; the file system change monitor is deprecated [4]
Syslog and NetFlow receiversYes — syslog over UDP or TCP; NetFlow v5 and IPFIXPartly — TCP and UDP inputs can listen for syslog [5]; NetFlow not in the sources reviewed
Masking on the hostYes — built-in detectors and your own patterns, before anything is stored or sentPartly — documented on a heavy forwarder or indexer [6]; force_local_processing on a UF increases CPU and memory use [12]
Splunk output (S2S, HEC)Yes — cooked S2S (9997) to a pool of indexers, and HEC (8088)Yes — the forwarder protocol, or HTTP output to HEC; "not both at the same time" [7]
Syslog, Snare and JSON outputYes — syslog, Snare, NDJSON and raw relay, over UDP, TCP or TLS, alongside SplunkPartly — raw TCP to third parties, without filtering or routing; no syslog output processor [8]
OpenTelemetry (OTLP) outputYes — OTLP over HTTP; detailsNot described in the sources reviewed — Splunk documents the tcpout and httpout output processors [7]
Delivery buffering and acknowledgementYes — disk-backed delivery per destination, with optional indexer acknowledgementYes — optional indexer acknowledgement [7]; persistent queues for some inputs [9]
Central managementYes — DPLens Manager, includedYes — agent management (deployment server before 10.0) distributes configurations and apps [10]
Licensing modelPer agent and per syslog or NetFlow receiver; no per-GB cost; works offlineThe forwarder licence "is applied automatically"; on ingest-based licences, data is metered when indexed [2]
Telemetry and call-homeNone — no telemetry, no licensing service, no control planeNot covered in the sources reviewed
Signed releases and SBOMYes — Authenticode-signed and timestamped; CycloneDX and SPDX SBOMsPartly — checksums and signature files on the download page; no SBOM mentioned [11]

Deciding

DPLens is the right choice when

  • Windows event volume drives your Splunk licence.
  • Personal or card data must be masked on the machine.
  • You send to Splunk and to another SIEM or an OpenTelemetry Collector, or are migrating between them.
  • You want central configuration, fleet health and upgrades on your own infrastructure, with nothing calling home.

Sources

Where the Universal Forwarder details come from

Last reviewed 1 October 2026, from Splunk's public documentation, download page and blog; details may since have changed.

DPLens performance figures: internal lab benchmark, 23 September 2026 (method). Splunk, Splunk Universal Forwarder and other product names are trademarks of their respective owners. They are used here only to describe what DPLens interoperates with and is compared to. DPLens is not affiliated with or endorsed by Splunk. Tell us about anything out of date.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.