Guides

Windows logging guides for SIEM and detection engineers.

Practical guides to collecting Windows logs well: what to keep, what to cut, and how to change agents without losing data or breaking searches. They're written to be useful whichever tools you run, with DPLens shown as one way to do it.

In short

DPLens publishes two Windows logging guides for SIEM and detection engineers: how to filter the noisiest Windows Security Event IDs without losing detections, and a step-by-step migration from the Splunk Universal Forwarder. Both cite Microsoft and vendor documentation and are dated, and both are useful whichever agent you run.

How these are written

Useful first, product second

The guides are written for engineers who may never buy DPLens. Microsoft facts, such as what an Event ID records, which audit subcategory produces it and what Microsoft recommends, are checked against Microsoft Learn and cited. Where we show DPLens, every step comes from the published 1.0 documentation, and any arithmetic is marked as illustrative.

DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. For product detail, the DPLens documentation is the reference manual. For the problems behind the guides, see SIEM cost reduction, Windows Event Log collection and the DPLens vs Splunk Universal Forwarder comparison.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.