These are the notes for the 1.0 documentation set. Every release has its own copy of this manual — use the version picker at the top of the page to read the notes for another release.
1.0
The first general release of DPLens.
Collecting
- Windows Event Log. One source collects any number of channels, including custom ones. Filter by severity, by event ID, by provider, or with your own event query — the filter is compiled into the channel's own query, so events you do not want are never read.
- Log files. A path or a wildcard. Rotated files are followed, new matching files are picked up, and UTF-8 and UTF-16 are detected for you.
- File integrity. Watch a file, a folder or a wildcard on a schedule. Changes arrive as events like any other. Very large files are tracked by their properties rather than by reading them, so one file cannot dominate a scan.
- Syslog. Receive from firewalls, switches and appliances over UDP or TCP.
- NetFlow and IPFIX. NetFlow v5 and IPFIX over UDP, IPFIX over TCP.
Collection positions are checkpointed, so a restart, an upgrade or a pause resumes where it stopped rather than re-reading or skipping.
Processing
One pipeline, six stages, applied in a fixed order: filter, parse and normalise, aggregate, enrich, mask, rate control. You can run more than one pipeline and route sources to them independently.
- Masking runs before anything is written to a destination's disk cache or sent, so a value a rule rewrites never reaches disk or the wire.
- Patterns you write run on an engine that does not backtrack, so a pattern cannot stall the pipeline.
- Every drop, mask, aggregation, failover and policy activation increments a counter the console renders, attributed to the rule that caused it.
Delivering
- Syslog (RFC 3164 and RFC 5424), Snare, NDJSON, and the Splunk forwarder and HTTP Event Collector protocols.
- UDP, TCP and TLS, with certificate validation on by default and mutual TLS where your receiver requires it.
- Failover and pools: list more than one address and DPLens moves between them, reporting which member is carrying traffic.
- A disk cache per destination, 1 GB by default and sized by you, so an outage queues events instead of discarding them. The console shows how many hours of your measured traffic a given size holds.
Running it
- A local web console over HTTPS, on loopback by default. Remote access is off until you turn it on, and then only from networks you list.
- Staged changes: edits are collected and applied together, and an apply that fails rolls back to the configuration that was running.
- Recommendations that read the machine and suggest collection you do not yet have.
- A live stream of events as they pass through the pipeline, showing the masked form — because that is what leaves.
- A tamper-evident audit log: every sign-in, apply, rollback, password change, certificate installation and licence change, hash-chained so a record cannot be altered or removed without breaking the chain.
- Two processes: collection runs as a virtual service account with only the privileges it needs, and the console host runs separately with fewer. A fault in the web interface cannot become a fault in collection.
Installing and deploying
- A Windows Installer package with silent installation and a full property set for unattended builds.
- The deployment MSI:
dp-deploycaptures a machine you have configured — configuration, certificates, secrets, console password — encrypts it under a deployment key shown to you once, and builds one installer package that carries it together with a list of licence keys. Any tool that runsmsiexecdeploys it; the installer reads the key from an administrators-only location and deletes it. - Push:
dp-deploy pushinstalls or updates a list of hosts over Windows Remote Management, with a canary batch, bounded concurrency and an abort threshold; domain hosts with Kerberos, workgroup hosts over TLS with a pinned or trusted listener certificate. - A guided wizard:
dp-deploywith no arguments walks from capture to deployment and saves a plan file that replays without prompts. - Deployment through Group Policy as an assigned package, with the key delivered by Group Policy Preferences; recipes for Intune, Configuration Manager, RMM tools and cloud images.
- A transform bundle builder for secret-free configurations that validates your configuration and your licence before you roll anything out.
- Guidance for golden images and VDI clones, including what must not be baked into an image.
Licensing and verification
- Offline licence keys, verified against a key built into the program. There is no licensing service to reach and no telemetry of any kind.
- Released packages are signed and published with SHA-256 checksums and a software bill of materials.
Known limitations in 1.0
- Windows x64 only. There is no 32-bit build and no ARM64 build, and no build for any other operating system.
- The console manages one machine. Each agent is configured on its own machine or by the configuration you deploy to it; there is no central console that manages an estate from one screen.
- Configuration at scale is file-based. Use Group Policy and the deployment bundle to roll a configuration across an estate.
- The syslog and NetFlow receivers each use a licence seat, so the seat count in your key limits how many devices' receivers you can enable.
- Windows Server Core is supported, but you will need a browser on another machine to reach the console, which means enabling remote access.
Build releases
DPLens build numbers count commits, so 1.0.912 is a build of the 1.0 release. Build releases within 1.0 are listed here as they ship, newest first, with what changed in each. A build release never changes how you configure the agent — your configuration file, licence and collection positions carry across.
Earlier releases
1.0 is the first release, so there are none. When a later release ships, this page is frozen with 1.0's notes and the new release gets its own copy.