Syslog is the most widely accepted way into a SIEM. DPLens speaks both the modern structured form and the older one.
| Format | Use it for |
|---|---|
syslog-5424 | RFC 5424. Precise timestamps, structured data, no length limit of its own. Prefer this. |
syslog-3164 | RFC 3164. The older line format, for receivers that require it. |
Over TLS
The recommended configuration.
destinations:
- type: tls
name: siem
params:
address: "siem.example.com:6514"
failover_addresses: "siem-2.example.com:6514"
sni: "siem.example.com"
ca_file: "C:\\ProgramData\\DPLens\\ca\\siem-ca.pem"
format: "syslog-5424"
framing: "octet-counted"
facility: "13"
severity: "5"
app_name: "dplens"
cache_max_bytes: "1073741824"
cache_full_policy: "block-upstream"
| Setting | Notes |
|---|---|
address | Conventionally port 6514 for syslog over TLS |
ca_file | Your authority's bundle. Omit to use the Windows trust store. |
sni | The name to present and verify against, when it differs from the address |
framing | Use octet-counted on a stream — see below |
Certificate validation is on. Turning it off (tls_insecure_skip_verify) removes the guarantee that you are talking to your SIEM at all; use it only while testing, and never leave it on.
Mutual TLS
If your SIEM requires the agent to present a certificate:
client_cert_handle: "secret://siem/client-cert"
client_key_handle: "secret://siem/client-key"
Seal both first:
type client.pem | "C:\Program Files\DPLens\dplens.exe" --set-secret secret://siem/client-cert
type client.key | "C:\Program Files\DPLens\dplens.exe" --set-secret secret://siem/client-key
Set both or neither.
Over TCP
The same, without encryption. Use it only on a network you control.
destinations:
- type: tcp
name: siem
params:
address: "siem.example.com:514"
format: "syslog-5424"
framing: "octet-counted"
Over UDP
destinations:
- type: udp
name: legacy-siem
params:
address: "203.0.113.20:514"
format: "syslog-3164"
facility: "13"
severity: "5"
No delivery guarantee. See Choosing a destination. Keep messages inside your receiver's datagram limit — many will not reassemble a fragmented one.
Framing on a stream
A receiver reading syslog over TCP or TLS has to know where one message ends and the next begins.
framing | How it works | Use when |
|---|---|---|
octet-counted | Each message is prefixed with its length | Your receiver supports it. Recommended — a message containing a newline cannot be split. |
lf | Messages are separated by a newline | Your receiver only understands newline separation |
If your SIEM shows events truncated or run together, this is almost always the setting to change.
The header fields
| Setting | What it sets | Default |
|---|---|---|
facility | The syslog facility, 0–23 | 1 |
severity | The severity, 0–7 | 6 |
hostname | The host name in the header | This machine's name |
app_name | The application name | dplens |
enterprise_id | The private enterprise number used in structured data | 32473 |
The default, 32473, is the number IANA reserves for documentation and examples. If your receiver keys on the enterprise number, set your organisation's own registered number instead.
Set facility to whatever your SIEM routes on — 13 (log audit) is a common choice for security data.
Timestamps
Timestamps are written in UTC unless you change it in Settings. RFC 5424 carries a precise timestamp with an offset; RFC 3164's is lower resolution and carries no year, which is one more reason to prefer 5424 where you can.
Checking it works
- Add the destination and map a pipeline to it.
- Use Send test event from a source's row menu.
- Watch it on Live stream with this destination selected — you see the exact bytes sent.
- Confirm it arrived in your SIEM.
If the Destinations page shows a cached backlog, the agent cannot reach the receiver. Check the address, the firewall, and — for TLS — whether the certificate validates.