Destinations

Sending syslog

RFC 5424 and RFC 3164 syslog over TLS, TCP or UDP.

Syslog is the most widely accepted way into a SIEM. DPLens speaks both the modern structured form and the older one.

FormatUse it for
syslog-5424RFC 5424. Precise timestamps, structured data, no length limit of its own. Prefer this.
syslog-3164RFC 3164. The older line format, for receivers that require it.

Over TLS

The recommended configuration.

destinations:
  - type: tls
    name: siem
    params:
      address: "siem.example.com:6514"
      failover_addresses: "siem-2.example.com:6514"
      sni: "siem.example.com"
      ca_file: "C:\\ProgramData\\DPLens\\ca\\siem-ca.pem"
      format: "syslog-5424"
      framing: "octet-counted"
      facility: "13"
      severity: "5"
      app_name: "dplens"
      cache_max_bytes: "1073741824"
      cache_full_policy: "block-upstream"
SettingNotes
addressConventionally port 6514 for syslog over TLS
ca_fileYour authority's bundle. Omit to use the Windows trust store.
sniThe name to present and verify against, when it differs from the address
framingUse octet-counted on a stream — see below

Certificate validation is on. Turning it off (tls_insecure_skip_verify) removes the guarantee that you are talking to your SIEM at all; use it only while testing, and never leave it on.

Mutual TLS

If your SIEM requires the agent to present a certificate:

      client_cert_handle: "secret://siem/client-cert"
      client_key_handle: "secret://siem/client-key"

Seal both first:

type client.pem | "C:\Program Files\DPLens\dplens.exe" --set-secret secret://siem/client-cert
type client.key | "C:\Program Files\DPLens\dplens.exe" --set-secret secret://siem/client-key

Set both or neither.

Over TCP

The same, without encryption. Use it only on a network you control.

destinations:
  - type: tcp
    name: siem
    params:
      address: "siem.example.com:514"
      format: "syslog-5424"
      framing: "octet-counted"

Over UDP

destinations:
  - type: udp
    name: legacy-siem
    params:
      address: "203.0.113.20:514"
      format: "syslog-3164"
      facility: "13"
      severity: "5"

No delivery guarantee. See Choosing a destination. Keep messages inside your receiver's datagram limit — many will not reassemble a fragmented one.

Framing on a stream

A receiver reading syslog over TCP or TLS has to know where one message ends and the next begins.

framingHow it worksUse when
octet-countedEach message is prefixed with its lengthYour receiver supports it. Recommended — a message containing a newline cannot be split.
lfMessages are separated by a newlineYour receiver only understands newline separation

If your SIEM shows events truncated or run together, this is almost always the setting to change.

The header fields

SettingWhat it setsDefault
facilityThe syslog facility, 0–231
severityThe severity, 0–76
hostnameThe host name in the headerThis machine's name
app_nameThe application namedplens
enterprise_idThe private enterprise number used in structured data32473

The default, 32473, is the number IANA reserves for documentation and examples. If your receiver keys on the enterprise number, set your organisation's own registered number instead.

Set facility to whatever your SIEM routes on — 13 (log audit) is a common choice for security data.

Timestamps

Timestamps are written in UTC unless you change it in Settings. RFC 5424 carries a precise timestamp with an offset; RFC 3164's is lower resolution and carries no year, which is one more reason to prefer 5424 where you can.

Checking it works

  1. Add the destination and map a pipeline to it.
  2. Use Send test event from a source's row menu.
  3. Watch it on Live stream with this destination selected — you see the exact bytes sent.
  4. Confirm it arrived in your SIEM.

If the Destinations page shows a cached backlog, the agent cannot reach the receiver. Check the address, the firewall, and — for TLS — whether the certificate validates.