Every page in this release, with its section headings. Use your browser's find (Ctrl+F) to search the whole manual at once.
Documentation
DPLens documentation
Install, configure and operate the DPLens Windows log collection agent.
Getting started
Requirements
Supported Windows versions, what to provision, and the ports and permissions DPLens needs.
Installing DPLens
Choose the installation method that suits how many machines you are deploying to.
Installing from the MSI
Install interactively or silently, and the full list of installer options.
Your first hour
From a fresh installation to events arriving at your SIEM, in about ten steps.
Upgrading and uninstalling
Upgrade in place, repair a damaged installation, or remove DPLens cleanly.
Configuration
How DPLens is configured
Where the files live, how a change takes effect, and what each part of agent.yaml means.
Configuration reference
Every source, destination and processing stage, with the settings each one accepts.
Configuration examples
Worked configurations you can copy, from a first collection to filtering, masking and fan-out.
- The simplest thing that works
- Syslog over TLS, with failover
- Collecting several channels at once
- Keeping only what you care about
- Collapsing repeats
- Masking sensitive data
- Capping how much you send
- Normalising field names
- Tailing a log file
- Watching files for change
- Receiving syslog from other devices
- Sending to two places at once
- Running two pipelines
- A pipeline that pauses instead of queueing
- Next
The console
Using the console
Signing in, finding your way around, and how staged changes, apply and roll back work.
Overview
How much you are collecting, what each stage removes, and what is being delivered.
Recommendations
What this machine has that is worth collecting, worked out locally.
Sources
The collectors on this machine, and every option in the add-source wizard.
Pipeline
What happens to events between collection and delivery, stage by stage.
Destinations
Where events go, how delivery is holding up, and every option in the destination wizard.
Live stream
Watch events leave, in real time, exactly as the destination receives them.
Settings and audit
Agent settings, console access, security, resources, licence and the audit log.
Replacing the console certificate
Front the console with a certificate from your own authority, so browsers stop warning.
Destinations
Choosing a destination
Which transport and format to use, and what each one guarantees.
Sending syslog
RFC 5424 and RFC 3164 syslog over TLS, TCP or UDP.
Sending to a Snare collector
The Snare tab-separated format, over TCP, TLS or UDP.
Sending NDJSON
One JSON object per line — the format that preserves the most.
Sending to Splunk
The forwarder protocol and the HTTP Event Collector, with index, host, source and sourcetype.
Deploying
Deployment options
Which approach suits your estate, and how they differ.
The deployment MSI
Capture a configured machine into one installer package that carries configuration, certificates, secrets and licence keys, and install it anywhere.
The deployment wizard
Run dp-deploy with no arguments and let it walk you from a configured machine to a deployed fleet, then replay the same choices without the prompts.
Pushing to hosts
Install or update a list of hosts from your workstation over Windows Remote Management, with a canary batch and an abort threshold.
Golden images and VDI clones
Bake DPLens into an image safely — what to include, and what every clone discards.
Group Policy
Deploy the deployment MSI with Software Installation and deliver the key with Group Policy Preferences — or a secret-free configuration with a transform and no key at all.
Intune, Configuration Manager, RMM and cloud images
Deploy the deployment MSI with the tool you already use — stage the key, run msiexec, detect the marker.
The deployment bundle
What a bundle folder contains, its manifest, and the transform bundle for configurations that need no secrets.
Operations
Operations
Running DPLens day to day — the service, permissions, logs, health, backup and upgrades.
The service and its permissions
Which account DPLens runs as, what it can reach, and how its folders are protected.
Logs and health
Where DPLens reports on itself, and how to tell whether it is well.
Backup and recovery
What to back up, what cannot be backed up, and how to rebuild a machine.
Troubleshooting
What to check when something is not working, in the order worth checking it.
Licence and security
Licensing
Applying a key, what it covers, and what happens as it approaches expiry.
Security
How DPLens is built and signed, what it stores, what it never does, and how to report a vulnerability.
Releases
Release notes
What is in this release of DPLens, and what each build release changed.
Verifying a download
Check the checksum and the signature, and read the bill of materials, before you install.