Comparison
DPLens vs the Splunk Universal Forwarder on Windows.
The Universal Forwarder sends Windows events into Splunk as they are, to be metered at the indexer. DPLens filters and masks them on the host first, keeps your index and sourcetype, and can add a non-Splunk destination at the same time.
In short
Choose DPLens if Windows event volume drives your Splunk licence or personal data must not leave the server unmasked. It filters and masks events on the host before Splunk meters them, delivers over cooked S2S or HEC with your existing index and sourcetype, and can feed a syslog SIEM or an OpenTelemetry Collector at the same time. DPLens Manager, included in every subscription, configures, monitors and upgrades the fleet centrally, and you can run DPLens alongside the Universal Forwarder (UF) until the data proves itself.
The case for DPLens
Why teams choose DPLens over the Universal Forwarder
DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. Numbers in brackets refer to the sources below.
01
Reduce where the events are created
On ingest-based licences, Splunk meters data when it is indexed [2]. The UF can allow or deny events by event code or a regular expression on event fields, and drop message text [3]; further filtering is a heavy forwarder feature [1]. Ingest Actions [13] and Edge Processor also drop data before it is metered, but on a tier after the full stream has crossed your network. DPLens adds field conditions, collapsed repeats and per-machine rate caps on the host, counting every removal against its rule. Size it with the savings calculator.
02
Mask before it leaves the server
Splunk documents anonymisation on a heavy forwarder or indexer [6]; Ingest Actions run on indexers, heavy forwarders and Splunk Cloud Platform [13]. DPLens masks card numbers, email and IP addresses, phone numbers, UK NI and US social security numbers, and your own patterns, on the server, before anything is stored or sent.
03
Keep your index and sourcetype
Cooked S2S on 9997 to a pool of indexers, or HEC on 8088, with index, host, source and sourcetype set per source. Events arrive in the familiar flattened Windows format or as the raw event XML, so your searches and dashboards keep working; confirm it side by side in the parallel run.
04
Measured on a busy channel
In our lab, DPLens delivered about 26,000–27,500 events per second on an 8-core Xeon E5-2430 v2 (Snare, S2S and NDJSON formats), at about 0.1 ms of CPU per event (method and caveats; lab figures, not a guarantee). Measure your current agent on the same server during your parallel run.
05
A non-Splunk destination alongside Splunk
A UF can forward raw TCP to a third party, but cannot route it per event and has no syslog output [8]. One DPLens pipeline feeds several destinations at once: Splunk plus syslog over TLS, Snare, NDJSON or OTLP to an OpenTelemetry Collector, for a SIEM migration or a second copy.
06
Central management included
DPLens Manager gives you central configuration, fleet health monitoring, and deployment and upgrades for every agent. It is self-hosted, air-gap capable and included in every subscription.
07
FIM included, no per-GB price
Scheduled file integrity monitoring runs in the same agent and licence. DPLens is priced per agent, plus a seat per syslog or NetFlow receiver (never per sending device). Licensing works offline and nothing calls home.
08
Secure by design
Signed releases with CycloneDX and SPDX SBOMs, a tamper-evident audit trail, least privilege and no telemetry. See the Trust Centre.
In July 2026 Splunk announced generally available log ingestion with its OpenTelemetry Collector, starting with Linux; it says Windows receivers, including windowseventlog, follow [14]. DPLens is Windows-native today, and delivers OTLP over HTTP to that Collector.
Low-risk change
Switching is low-risk
The UF stays until the data proves itself. The migration guide maps your Universal Forwarder inputs and outputs line by line.
Run alongside
Install DPLens next to the UF, sending to the same indexers, index and sourcetype. Keep the overlap short: on ingest-based licences both copies count against your licence.
Compare in Splunk
Search both, Event ID by Event ID, and run your saved searches. Every difference should be one your filters explain.
Cut over by server group, with a rollback
Disable the UF rather than uninstalling it. To roll back, start it again: it resumes from its own checkpoint (details).
At scale
Running it across thousands of servers
- Central management: DPLens Manager, included in every subscription, gives you central configuration, fleet health monitoring, and deployment and upgrades. It is self-hosted and air-gap capable.
- Install your way: the signed installer also deploys through Group Policy, Intune, Configuration Manager or an RMM.
- Images and VDI: golden images and VDI are supported deployment methods, and generalised clones start with fresh state.
- Upgrades: in place, keeping configuration, licence, secrets, collection positions and cache.
- Health: watch the fleet in DPLens Manager, and alert in Splunk on hosts that stop sending and on the signals the documentation lists.
- Support: every subscription includes support 9am to 5pm UK time, Monday to Friday, and enhanced support is available as a paid option (support and lifecycle).
Feature by feature
DPLens and the Universal Forwarder compared
UF entries come from Splunk's documentation; DPLens entries from the DPLens documentation and DPLens Ltd.
| Capability | DPLens | Splunk Universal Forwarder |
|---|---|---|
| Windows Event Log filtering | Yes — any channel, with field conditions, aggregation and rate caps on the host | Yes — allow and deny lists by event code, or key and regular expression; message text can be dropped [3] |
| File integrity monitoring | Yes — files, folders and wildcards, scanned every 15 minutes, hourly or daily | Partly — through object-access auditing; the file system change monitor is deprecated [4] |
| Syslog and NetFlow receivers | Yes — syslog over UDP or TCP; NetFlow v5 and IPFIX | Partly — TCP and UDP inputs can listen for syslog [5]; NetFlow not in the sources reviewed |
| Masking on the host | Yes — built-in detectors and your own patterns, before anything is stored or sent | Partly — documented on a heavy forwarder or indexer [6]; force_local_processing on a UF increases CPU and memory use [12] |
| Splunk output (S2S, HEC) | Yes — cooked S2S (9997) to a pool of indexers, and HEC (8088) | Yes — the forwarder protocol, or HTTP output to HEC; "not both at the same time" [7] |
| Syslog, Snare and JSON output | Yes — syslog, Snare, NDJSON and raw relay, over UDP, TCP or TLS, alongside Splunk | Partly — raw TCP to third parties, without filtering or routing; no syslog output processor [8] |
| OpenTelemetry (OTLP) output | Yes — OTLP over HTTP; details | Not described in the sources reviewed — Splunk documents the tcpout and httpout output processors [7] |
| Delivery buffering and acknowledgement | Yes — disk-backed delivery per destination, with optional indexer acknowledgement | Yes — optional indexer acknowledgement [7]; persistent queues for some inputs [9] |
| Central management | Yes — DPLens Manager, included | Yes — agent management (deployment server before 10.0) distributes configurations and apps [10] |
| Licensing model | Per agent and per syslog or NetFlow receiver; no per-GB cost; works offline | The forwarder licence "is applied automatically"; on ingest-based licences, data is metered when indexed [2] |
| Telemetry and call-home | None — no telemetry, no licensing service, no control plane | Not covered in the sources reviewed |
| Signed releases and SBOM | Yes — Authenticode-signed and timestamped; CycloneDX and SPDX SBOMs | Partly — checksums and signature files on the download page; no SBOM mentioned [11] |
Deciding
DPLens is the right choice when
- Windows event volume drives your Splunk licence.
- Personal or card data must be masked on the machine.
- You send to Splunk and to another SIEM or an OpenTelemetry Collector, or are migrating between them.
- You want central configuration, fleet health and upgrades on your own infrastructure, with nothing calling home.
Check it yourself
In the documentation
- Replacing an existing forwarder: run alongside, compare, switch
- Index, host, source and sourcetype
- Masking sensitive data
- Deployment options
Related: Splunk Universal Forwarder replacement, Splunk integration, OpenTelemetry integration, DPLens vs Splunk Edge Processor, Trust Centre, licensing model and all comparisons.
Sources
Where the Universal Forwarder details come from
- [1] Types of forwarders (Splunk Enterprise 10.6) — help.splunk.com
- [2] Licenses and distributed deployments — help.splunk.com
- [3] Monitor Windows event log data with Splunk Enterprise — help.splunk.com
- [4] Monitor file system changes on Windows — help.splunk.com
- [5] Get data from TCP and UDP ports — help.splunk.com
- [6] Anonymize data — help.splunk.com
- [7] Configure forwarding with outputs.conf (Universal Forwarder manual 10.6) — help.splunk.com
- [8] Forward data to third-party systems (10.6) — help.splunk.com
- [9] Use persistent queues to help prevent data loss — help.splunk.com
- [10] About agent management (10.0) — help.splunk.com
- [11] Splunk Universal Forwarder download page — splunk.com
- [12] props.conf specification (10.2.0),
force_local_processing— help.splunk.com - [13] Ingest Actions requirements — help.splunk.com
- [14] Introducing fully supported log ingestion with the Splunk OpenTelemetry Collector (Splunk blog, 31 July 2026) — splunk.com
See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.