What you need once DPLens is installed and working.
- The service and its permissions — which account it runs as, what it can reach, and how the folders are protected.
- Logs and health — where DPLens reports on itself, and how to tell whether it is well.
- Backup and recovery — what to back up, and how to rebuild a machine.
- Troubleshooting — what to check when something is not working.
The short version
| Task | How |
|---|---|
| Start or stop | sc.exe start dplens / sc.exe stop dplens |
| Check it is running | sc.exe query dplens |
| See what it is doing | The console, on https://localhost:8443 |
| Change configuration | The console, or edit agent.yaml and restart |
| Check a configuration file | dplens.exe --validate-only --config <file> |
| Set a secret | dplens.exe --set-secret secret://<name> |
| Check the licence | dplens.exe --verify-licence <file> |
| Back up | C:\ProgramData\DPLens\config\ |
Run these from an elevated prompt; the program is at C:\Program Files\DPLens\dplens.exe.
What it does on its own
DPLens is built to keep running without attention.
- A failed component is restarted, not the whole agent. If it keeps failing, it is quarantined so it cannot affect anything else, and the rest keeps collecting.
- Positions are checkpointed, so a restart, a crash or an upgrade resumes where it stopped rather than re-reading or skipping.
- An unreachable destination queues to disk and drains when it recovers.
- Folder permissions are re-applied at every start, so a change made by something else is corrected.
- Nothing is dropped silently. Every drop, mask, aggregation, failover and policy change increments a counter the console shows.
What it will not do on its own is update itself, or reach out to any service of ours. There is no auto-update and no telemetry.
What to watch
If you are adding DPLens to a monitoring regime, these are the signals worth alerting on:
| Signal | Where | Why |
|---|---|---|
| Agent health not Healthy | Overview | A source or destination has a problem |
| A destination in cached backlog for longer than you expect | Destinations | Delivery is failing; the cache is finite |
| Cache depth approaching its cap | Destinations, Settings → Resources | You are about to start dropping, or pausing |
| Non-zero drops you did not configure | Overview | Something is discarding events |
| Licence approaching expiry | Settings → Licence | Collection stops after the grace period |
| The service not running | sc.exe query dplens | Nothing is being collected |
The audit log records changes rather than health, but a configuration change you did not expect is worth an alert of its own — see Settings and audit.