Getting started

Requirements

Supported Windows versions, what to provision, and the ports and permissions DPLens needs.

DPLens is a single executable with no runtime prerequisites. If the machine runs a supported version of Windows, you can install it.

Supported operating systems

WindowsSupported
Windows Server 2025Yes
Windows Server 2022Yes
Windows Server 2019Yes
Windows Server 2016Yes
Windows 11Yes
Windows 10Yes

Architecture: 64-bit Intel or AMD (x64) only. There is no 32-bit build, and ARM64 is not supported in this release.

Windows Server Core is supported. The console is a web interface served by the agent, so it does not need a desktop — you reach it from a browser on another machine if you enable remote access, or through a local browser if one is installed.

What you do not need

DPLens ships as one executable and its installer. There is nothing else to install first:

What to provision

These are provisioning allowances, not a performance specification. What the agent actually uses depends on your configuration and your event rate.

ResourceAllow
Disk — program files30 MB
Disk — working state1 GB, plus your cache sizing below
Memory150 MB
CPULow at idle; a busy pipeline scales with your event rate

Sizing the disk cache

Each destination keeps its own on-disk cache so that an outage queues events instead of losing them. The cache holds 1 GB per destination by default, and you set the size per destination.

To size it, estimate how long an outage you want to survive and how many events a second that destination receives. A useful rule of thumb is that a cached event costs roughly its own delivered size. The console does this arithmetic for you: when you set a cache size on a destination it shows how many hours of your measured traffic that size holds.

Plan the volume so the cache can reach its full size without filling the disk. You can also reserve free space on the volume, below which DPLens stops growing the cache — see Destinations.

Ports

Inbound — only if you enable these features

PortProtocolUsed byDefault
8443TCPThe console, over HTTPSLoopback only
514UDP or TCPSyslog receiver, if you add oneOff
2055UDP or TCPNetFlow and IPFIX receiver, if you add oneOff

The console listens on localhost only unless you explicitly turn on remote access, and remote access requires you to list the networks allowed to reach it. Nothing else listens until you configure it.

Outbound — to your SIEM

These are the conventional ports for each destination type. Yours may differ; you set the address on the destination.

PortProtocolDestination type
514UDP or TCPSyslog, Snare
6514TCPSyslog over TLS
2514TCPNDJSON collector
9997TCPSplunk, forwarder protocol
8088TCPSplunk HTTP Event Collector

Permissions

To install

Local administrator rights on the machine. The installer registers a Windows service, creates its data folders and sets their permissions.

To run

The agent runs as a Windows service. By default it uses a virtual service account created for it, NT SERVICE\dplens, holding only the privileges it needs. This account has no password, cannot log on interactively, and cannot be used anywhere else.

You can install it to run as LocalSystem instead if your environment requires it, but the virtual service account is the recommended and default choice.

The console runs as a separate, lower-privileged process under its own account. A fault in the web interface cannot reach the collection service's privileges.

To read the Security event log

Reading the Security channel requires elevated rights, which the service account has by virtue of being a service. No additional Group Policy change is needed. Other channels, including Application, System and most Applications and Services logs, are readable without any special grant.

To read log files

The service account needs read access to any file or folder you point a file or file-integrity source at. If the path is on a network share, grant access to the computer account rather than to NT SERVICE\dplens, which exists only on the local machine.

Antivirus and application control

DPLens is an executable that reads event logs and files and makes outbound network connections. If you run application control such as AppLocker or Windows Defender Application Control, allow C:\Program Files\DPLens\dplens.exe by publisher or by path.

If your antivirus scans on read, exclude the agent's own state folder, C:\ProgramData\DPLens\state. The agent writes to it continuously, and scanning every write costs throughput on both products for no benefit.

Next

Go to Installing DPLens.