Getting started

Your first hour

From a fresh installation to events arriving at your SIEM, in about ten steps.

This walks a fresh installation through to events arriving at your SIEM. It assumes you have installed the MSI and have a licence key.

You will end up with one Windows Event Log source, one destination, a pipeline connecting them with masking switched on, and events you can watch flowing.

1. Open the console

On the machine itself, browse to:

https://localhost:8443

Your browser will warn about the certificate. That is expected: the agent generates its own certificate on first start, and your browser has no reason to trust it. Continue past the warning for now. When you are ready to use a certificate from your own authority, see Replacing the console certificate.

If you set UI_PORT during installation, use that port instead.

2. Sign in

If you set ADMIN_PASSWORD during installation, sign in as admin with that password.

If you did not, the console asks you to create the account now. Choose a strong password; there is no recovery path, because the password is stored only as a hash. If you lose it, an administrator on the machine can set a new one from the command line.

3. Apply your licence

Until DPLens is licensed it will collect nothing and send nothing. The console runs, and everything is configurable, but the data plane is held.

Go to Settings and audit → Licence, paste your key into Apply a licence key, and save. The page then shows what the licence covers and when it expires.

If you supplied LICENCE_KEY or LICENCE_FILE at install time this is already done, and the page simply shows the details.

See Licensing for what a licence covers and what happens as it nears expiry.

4. See what this machine can offer

Go to Recommendations.

DPLens inspects the machine — its roles, its services, its disks, its audit policy — and suggests sources worth collecting, ranked by how useful they usually are. The scan runs locally; nothing about your machine leaves it.

Each recommendation has an Add with defaults button, which is the quickest way to get a sensible source configured. You can adjust it afterwards.

5. Add a source

If you would rather choose for yourself, go to Sources → Add source.

For a first source, the Windows Security channel is the usual choice. In the wizard:

Save it. See Sources for every option.

6. Add a destination

Go to Destinations → Add destination.

Start from the preset that matches your receiver — for example Syslog SIEM — modern for syslog over TLS, or Splunk (S2S) for a Splunk indexer. The preset fills in the transport, port and format, and you supply the address.

Two things are worth setting now rather than later:

See Destinations for every option, and Choosing a destination for which transport to use.

7. Connect them with a pipeline

Go to Pipeline. If this is a fresh installation you will be offered a pipeline to create; otherwise use + New pipeline.

A pipeline takes one source, runs it through the stages you choose, and delivers to one or more destinations. Set the source to the one you added and map it to your destination.

8. Turn on masking

Before you send anything, decide what should not leave the machine.

On the Pipeline page, open the Mask stage. Add a rule for anything your events carry that should be redacted, hashed or tokenised — card numbers, national insurance numbers, email addresses, or a pattern of your own.

Masking runs before anything is written to the disk cache or sent, so a value a rule rewrites is not stored and not transmitted — and the console's own live stream shows the rewritten form, because that is what leaves.

See Pipeline for the full stage.

9. Review and apply

Your source, destination, pipeline and masking edits are all staged — none of them has taken effect yet. (If you took a recommendation in step 4 with Add with defaults, that one applied as you added it; everything else is waiting.)

The pending changes indicator at the top of the console shows how many changes are waiting. Open it, read the summary of what will change, and Apply.

If something is wrong with the new configuration, the apply is refused and your running configuration is untouched. If it applies but the agent does not come back healthy, you get a countdown and a Roll back button to return to the previous configuration.

10. Watch it work

Go to Live stream and choose your destination.

You should see events arriving, tagged with what happened to them. Rows carry a MASKED chip where a masking rule fired. If nothing appears, the troubleshooting guide starts with the usual causes.

Then go back to Overview. It shows how many events a second you are collecting, how much each stage is removing, and how much is being delivered. If you set a cost per gigabyte in Settings, it also shows what the reduction is worth.

Then what