DPLens is a single executable with no runtime prerequisites. If the machine runs a supported version of Windows, you can install it.
Supported operating systems
| Windows | Supported |
|---|---|
| Windows Server 2025 | Yes |
| Windows Server 2022 | Yes |
| Windows Server 2019 | Yes |
| Windows Server 2016 | Yes |
| Windows 11 | Yes |
| Windows 10 | Yes |
Architecture: 64-bit Intel or AMD (x64) only. There is no 32-bit build, and ARM64 is not supported in this release.
Windows Server Core is supported. The console is a web interface served by the agent, so it does not need a desktop — you reach it from a browser on another machine if you enable remote access, or through a local browser if one is installed.
What you do not need
DPLens ships as one executable and its installer. There is nothing else to install first:
- No .NET runtime. Nothing in DPLens runs on .NET.
- No Java.
- No Visual C++ redistributable. The runtime is linked into the executable.
- No database. State is held in files the agent manages.
- No agent management server. DPLens runs standalone.
- No internet access. The agent never contacts a licensing service and sends no telemetry. An air-gapped machine is a normal deployment.
What to provision
These are provisioning allowances, not a performance specification. What the agent actually uses depends on your configuration and your event rate.
| Resource | Allow |
|---|---|
| Disk — program files | 30 MB |
| Disk — working state | 1 GB, plus your cache sizing below |
| Memory | 150 MB |
| CPU | Low at idle; a busy pipeline scales with your event rate |
Sizing the disk cache
Each destination keeps its own on-disk cache so that an outage queues events instead of losing them. The cache holds 1 GB per destination by default, and you set the size per destination.
To size it, estimate how long an outage you want to survive and how many events a second that destination receives. A useful rule of thumb is that a cached event costs roughly its own delivered size. The console does this arithmetic for you: when you set a cache size on a destination it shows how many hours of your measured traffic that size holds.
Plan the volume so the cache can reach its full size without filling the disk. You can also reserve free space on the volume, below which DPLens stops growing the cache — see Destinations.
Ports
Inbound — only if you enable these features
| Port | Protocol | Used by | Default |
|---|---|---|---|
| 8443 | TCP | The console, over HTTPS | Loopback only |
| 514 | UDP or TCP | Syslog receiver, if you add one | Off |
| 2055 | UDP or TCP | NetFlow and IPFIX receiver, if you add one | Off |
The console listens on localhost only unless you explicitly turn on remote access, and remote access requires you to list the networks allowed to reach it. Nothing else listens until you configure it.
Outbound — to your SIEM
These are the conventional ports for each destination type. Yours may differ; you set the address on the destination.
| Port | Protocol | Destination type |
|---|---|---|
| 514 | UDP or TCP | Syslog, Snare |
| 6514 | TCP | Syslog over TLS |
| 2514 | TCP | NDJSON collector |
| 9997 | TCP | Splunk, forwarder protocol |
| 8088 | TCP | Splunk HTTP Event Collector |
Permissions
To install
Local administrator rights on the machine. The installer registers a Windows service, creates its data folders and sets their permissions.
To run
The agent runs as a Windows service. By default it uses a virtual service account created for it, NT SERVICE\dplens, holding only the privileges it needs. This account has no password, cannot log on interactively, and cannot be used anywhere else.
You can install it to run as LocalSystem instead if your environment requires it, but the virtual service account is the recommended and default choice.
The console runs as a separate, lower-privileged process under its own account. A fault in the web interface cannot reach the collection service's privileges.
To read the Security event log
Reading the Security channel requires elevated rights, which the service account has by virtue of being a service. No additional Group Policy change is needed. Other channels, including Application, System and most Applications and Services logs, are readable without any special grant.
To read log files
The service account needs read access to any file or folder you point a file or file-integrity source at. If the path is on a network share, grant access to the computer account rather than to NT SERVICE\dplens, which exists only on the local machine.
Antivirus and application control
DPLens is an executable that reads event logs and files and makes outbound network connections. If you run application control such as AppLocker or Windows Defender Application Control, allow C:\Program Files\DPLens\dplens.exe by publisher or by path.
If your antivirus scans on read, exclude the agent's own state folder, C:\ProgramData\DPLens\state. The agent writes to it continuously, and scanning every write costs throughput on both products for no benefit.
Next
Go to Installing DPLens.