Operations

Troubleshooting

What to check when something is not working, in the order worth checking it.

Start at the top and work down. Most problems are answered in the first two steps.

  1. Is the service running? sc.exe query dplens
  2. What does the console say? The health indicator, then Overview.

The service will not start

Check Windows Logs → System for the Service Control Manager's record, then check the configuration:

"C:\Program Files\DPLens\dplens.exe" --validate-only --config "C:\ProgramData\DPLens\config\agent.yaml"
CauseFix
The configuration file is invalidThe validator names the problem. Fix and start again.
The configuration file is unreadableCheck permissions with icacls C:\ProgramData\DPLens\config
The state folder was written by a newer versionThe machine ran a newer build before. Install that version, or uninstall with REMOVE_STATE=1 and start fresh.
The program file is missing or damagedRepair: msiexec /f dplens.msi /qn

The console will not open

SymptomCauseFix
Connection refusedThe console is switched off, or on a different portCheck settings.ui in the configuration file
Connection refused from another machineRemote access is off — the defaultTurn it on and set allowed networks in Settings → General
Connection refused from another machine, remote access onThe address is not in the allow-list, or the firewall blocks itCheck the list, then the firewall
Certificate warningThe self-signed certificateExpected. Install your own.
Sign-in rejectedWrong password, or locked out after repeated attemptsWait, or reset: dplens.exe --set-admin-password

Nothing is being collected

Is the agent licensed?

Settings and audit → Licence. Unlicensed, or past the grace period, the console runs and everything is configurable but no events flow. See Licensing.

Is the pipeline enabled?

A new installation ships with its pipeline switched off deliberately. Check the switch on Pipeline.

Is the source healthy and producing?

On Sources, check the health chip and the rate.

SourceCommon cause of silence
Windows Event LogThe channel is genuinely quiet, or is not enabled in Windows. Check it in Event Viewer.
Windows Event LogRead events already in the log is off and nothing new has happened. Expected.
Log fileThe path matches nothing. Check for typos and wildcards.
Log fileThe service account cannot read the path. Check permissions.
Log file on a shareAccess was granted to the service account rather than the computer account
Syslog / NetFlowThe firewall is blocking the port
Syslog / NetFlowThe sender is not in Allowed networks
File integrityNothing has changed since the last scan. Expected.

Is a filter dropping everything?

The funnel on Overview shows each stage's in and out. A stage with events in and none out is doing exactly what you told it.

Events are collected but not arriving

Check the Destinations page.

Cached backlog

The agent cannot deliver and is queueing on disk.

Check
Address and portTypos, and the wrong port for the transport
FirewallOutbound to that address and port
The receiverIs it running and accepting?
TLSDoes the certificate validate? Is ca_file right? Does the name match?
Splunk HECIs the token valid and the endpoint enabled?

Once you fix it, the queue drains automatically. Those events appear on Live stream tagged as replayed.

Delivering, but nothing in your SIEM

The events are leaving, so the problem is downstream.

Check
FormatDoes the receiver expect what you are sending? Watch Live stream to see the exact bytes.
FramingOn TCP or TLS, the wrong framing makes records run together or truncate. Try the other setting.
Index and sourcetypeFor Splunk, data lands somewhere your searches do not look
TimeEvents with an unexpected timestamp land outside the window you are searching

Something is being dropped

Every drop is counted and attributed on Overview.

CounterMeaningWhat to do
FilteredA filter rule dropped itIntended, if the rule is right
AggregatedCollapsed into a representativeIntended
Rate limitedThe cap was exceededRaise the cap, or accept it
Cache fullThe queue hit its cap and your policy is to dropIncrease the cache, or change the policy
Group limit reachedMore distinct aggregation groups than the maximumRaise the maximum, or group by fewer fields
Decode failuresA malformed message arrived at a receiverCheck the sending device
Missing templateNetFlow records arrived before their templateUsually settles; if it persists, check the exporter

A component is quarantined

It failed repeatedly and was stopped so it could not affect the rest. Fix the cause, then re-enable it — pause and resume from its row, or apply a configuration change.

Turn on the diagnostics file to find out why it failed. See Logs and health.

Disk is filling

Caches are the only thing that grows without bound if a destination stays down, and they are capped.

  1. Settings and audit → Resources shows total cache and per destination.
  2. Fix the unreachable destination, and the cache drains.
  3. If you cannot, reduce that destination's cache size, or change what happens when it fills.
  4. Set Keep free on the volume so a cache cannot take the last of the disk.

The diagnostics file is bounded by size limit × files kept, so it cannot be the cause unless configured very large.

Performance

SymptomLikely causeWhat to try
High CPUMessage rendering on a busy channelTurn rendering off unless your receiver needs it
High CPUComplex patterns in filter or mask rules on high volumeFilter at the source instead — an event never read costs nothing
Falling behindThe destination cannot keep upCheck whether acknowledgement is on; it trades throughput for a guarantee
Falling behindOne pipeline paced by a slow destinationGive the slow one its own pipeline so it cannot hold up the others

Getting help

Have ready:

Never send a licence key, a password, or the contents of the secret store. No support question needs them.