This walks a fresh installation through to events arriving at your SIEM. It assumes you have installed the MSI and have a licence key.
You will end up with one Windows Event Log source, one destination, a pipeline connecting them with masking switched on, and events you can watch flowing.
1. Open the console
On the machine itself, browse to:
https://localhost:8443
Your browser will warn about the certificate. That is expected: the agent generates its own certificate on first start, and your browser has no reason to trust it. Continue past the warning for now. When you are ready to use a certificate from your own authority, see Replacing the console certificate.
If you set UI_PORT during installation, use that port instead.
2. Sign in
If you set ADMIN_PASSWORD during installation, sign in as admin with that password.
If you did not, the console asks you to create the account now. Choose a strong password; there is no recovery path, because the password is stored only as a hash. If you lose it, an administrator on the machine can set a new one from the command line.
3. Apply your licence
Until DPLens is licensed it will collect nothing and send nothing. The console runs, and everything is configurable, but the data plane is held.
Go to Settings and audit → Licence, paste your key into Apply a licence key, and save. The page then shows what the licence covers and when it expires.
If you supplied LICENCE_KEY or LICENCE_FILE at install time this is already done, and the page simply shows the details.
See Licensing for what a licence covers and what happens as it nears expiry.
4. See what this machine can offer
Go to Recommendations.
DPLens inspects the machine — its roles, its services, its disks, its audit policy — and suggests sources worth collecting, ranked by how useful they usually are. The scan runs locally; nothing about your machine leaves it.
Each recommendation has an Add with defaults button, which is the quickest way to get a sensible source configured. You can adjust it afterwards.
5. Add a source
If you would rather choose for yourself, go to Sources → Add source.
For a first source, the Windows Security channel is the usual choice. In the wizard:
- Pick Windows Event Log.
- Choose the Security channel.
- Leave Read events already in the log switched off, so you start with new events rather than replaying history.
Save it. See Sources for every option.
6. Add a destination
Go to Destinations → Add destination.
Start from the preset that matches your receiver — for example Syslog SIEM — modern for syslog over TLS, or Splunk (S2S) for a Splunk indexer. The preset fills in the transport, port and format, and you supply the address.
Two things are worth setting now rather than later:
- A failover address. If your SIEM has more than one collector, list them. DPLens moves to the next one when the first stops accepting, and moves back when it recovers.
- The cache size. This is how much you are prepared to hold on disk during an outage. The page shows how many hours of your traffic the size you choose will hold.
See Destinations for every option, and Choosing a destination for which transport to use.
7. Connect them with a pipeline
Go to Pipeline. If this is a fresh installation you will be offered a pipeline to create; otherwise use + New pipeline.
A pipeline takes one source, runs it through the stages you choose, and delivers to one or more destinations. Set the source to the one you added and map it to your destination.
8. Turn on masking
Before you send anything, decide what should not leave the machine.
On the Pipeline page, open the Mask stage. Add a rule for anything your events carry that should be redacted, hashed or tokenised — card numbers, national insurance numbers, email addresses, or a pattern of your own.
Masking runs before anything is written to the disk cache or sent, so a value a rule rewrites is not stored and not transmitted — and the console's own live stream shows the rewritten form, because that is what leaves.
See Pipeline for the full stage.
9. Review and apply
Your source, destination, pipeline and masking edits are all staged — none of them has taken effect yet. (If you took a recommendation in step 4 with Add with defaults, that one applied as you added it; everything else is waiting.)
The pending changes indicator at the top of the console shows how many changes are waiting. Open it, read the summary of what will change, and Apply.
If something is wrong with the new configuration, the apply is refused and your running configuration is untouched. If it applies but the agent does not come back healthy, you get a countdown and a Roll back button to return to the previous configuration.
10. Watch it work
Go to Live stream and choose your destination.
You should see events arriving, tagged with what happened to them. Rows carry a MASKED chip where a masking rule fired. If nothing appears, the troubleshooting guide starts with the usual causes.
Then go back to Overview. It shows how many events a second you are collecting, how much each stage is removing, and how much is being delivered. If you set a cost per gigabyte in Settings, it also shows what the reduction is worth.
Then what
- Add the rest of your sources. Recommendations is a good checklist.
- Use the Filter stage to drop events nobody searches for. Reduction at the agent is the cheapest reduction there is.
- Once one machine is configured the way you want, export that configuration and deploy it to the rest.