DPLens is a single Windows agent that collects your logs, cuts them down to what you actually need, and delivers them to your SIEM.
It collects from Windows Event Log channels, log files, file-integrity changes, and inbound syslog and NetFlow. It filters, parses, aggregates, enriches, masks and rate-limits events on the machine that produced them. It then delivers them over syslog, Snare, NDJSON or Splunk transports, with failover and an on-disk cache that keeps events safe through an outage.
There is no cloud service, no control plane and no agent-to-vendor traffic. Everything runs on your machine, under your configuration.
Start here
- Requirements — supported Windows versions, what to provision, and which ports you will need.
- Installing DPLens — choose an installation method, then follow it through to a licensed, running agent.
- Your first hour — sign in, apply a licence, add a source and a destination, and watch events arrive.
Configuration
- How DPLens is configured — where the files live, how a change is applied, and what the top-level sections mean.
- Configuration reference — every source, destination and processing stage, with every setting it accepts.
- Configuration examples — worked, runnable configurations you can copy.
The console
- Using the console — signing in, finding your way around, and how staged changes, apply and roll back work.
- Page by page: Overview · Recommendations · Sources · Pipeline · Destinations · Live stream · Settings and audit
- Replacing the console certificate — front the console with a certificate from your own authority.
Sending events to your SIEM
- Choosing a destination — which transport and format to use.
- Syslog · Snare · NDJSON · Splunk
Deploying to a fleet
- Deployment options — which approach suits your estate.
- The deployment MSI — capture a configured machine into one package that carries configuration, certificates, secrets and licence keys.
- The deployment wizard —
dp-deploywith no arguments, from capture to rollout, with a replayable plan. - Pushing to hosts · Group Policy · Intune, Configuration Manager, RMM and cloud images
- The deployment bundle — what a bundle folder contains, and the transform bundle for secret-free configurations.
- Golden images and VDI clones
Running it
- Operations — the service, permissions, logs, health, backup and upgrades.
- Troubleshooting — what to check when something is not working.
Licence and security
- Licensing — applying a key, what it covers, and what happens as it approaches expiry.
- Security — how DPLens is built and signed, what it stores, and how to report a vulnerability.
Releases
- Release notes — what is in this release, and what each build release changed.
- Verifying a download — checksums, signatures and the software bill of materials.
This manual is published once per release. You are reading the 1.0 set; the version picker at the top of every page switches between them, and /docs/latest/ always points at the current release.