Guides
Windows logging guides for SIEM and detection engineers.
Practical guides to collecting Windows logs well: what to keep, what to cut, and how to change agents without losing data or breaking searches. They're written to be useful whichever tools you run, with DPLens shown as one way to do it.
In short
DPLens publishes two Windows logging guides for SIEM and detection engineers: how to filter the noisiest Windows Security Event IDs without losing detections, and a step-by-step migration from the Splunk Universal Forwarder. Both cite Microsoft and vendor documentation and are dated, and both are useful whichever agent you run.
The guides
Read a guide
Each guide opens with a short answer, then gives the working detail: Event IDs, audit subcategories, queries and configuration you can copy.
Detection engineering
The noisiest Windows Security Event IDs and how to filter them
Event IDs 4662, 4663, 4656, 4688, 5156, 5158, 5145, 4703 and more: what each records, which audit subcategory produces it, what you lose by dropping it, and narrower XPath and pipeline filters to use instead.
Read the guide →Migration
Migrating from the Splunk Universal Forwarder to DPLens
Inventory inputs.conf and outputs.conf, keep index and sourcetype so searches keep working, run both side by side, compare counts in Splunk, and cut over one server group at a time with a rollback.
How these are written
Useful first, product second
The guides are written for engineers who may never buy DPLens. Microsoft facts, such as what an Event ID records, which audit subcategory produces it and what Microsoft recommends, are checked against Microsoft Learn and cited. Where we show DPLens, every step comes from the published 1.0 documentation, and any arithmetic is marked as illustrative.
DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. For product detail, the DPLens documentation is the reference manual. For the problems behind the guides, see SIEM cost reduction, Windows Event Log collection and the DPLens vs Splunk Universal Forwarder comparison.
Reference
In the documentation
See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.