Documentation

DPLens documentation

Install, configure and operate the DPLens Windows log collection agent.

DPLens is a single Windows agent that collects your logs, cuts them down to what you actually need, and delivers them to your SIEM.

It collects from Windows Event Log channels, log files, file-integrity changes, and inbound syslog and NetFlow. It filters, parses, aggregates, enriches, masks and rate-limits events on the machine that produced them. It then delivers them over syslog, Snare, NDJSON or Splunk transports, with failover and an on-disk cache that keeps events safe through an outage.

There is no cloud service, no control plane and no agent-to-vendor traffic. Everything runs on your machine, under your configuration.

Start here

Configuration

The console

Sending events to your SIEM

Deploying to a fleet

Running it

Licence and security

Releases

This manual is published once per release. You are reading the 1.0 set; the version picker at the top of every page switches between them, and /docs/latest/ always points at the current release.