DPLens
DPLens
Contact us

Less noise. More signal. Lower cost.

A lightweight pipeline solution that puts your telemetry data back under your control. Shape it at source and route it anywhere. All whilst removing vendor lock-in and budget/security tradeoffs.

Observe

Every source, every host, one view of what is actually being collected.

Secure

Memory safe, split-privilege, tamper-evident — a solution you can defend in review.

Optimize

Filter, aggregate, reduce and shape your data at the edge, so budget doesn't compromise security.

Insight

Parsed and enriched at source, so events land search-ready in your Data Lake, Repository and/or SIEM.

Rich source support

Everything you need from your servers, and the devices around it.

One platform and complete control across every input. Single install, no forwarder sprawl, no vendor lock in and no central resource drain.

01

Windows Event Log

Native subscription to Security, System, Sysmon and any custom channel. XPath selection, bookmark checkpointing, rendered or raw XML.

02

Log files

Glob tailing with rotation, truncation and multiline handling. Positions survive restart; back-pressure never loses a line.

03

File integrity monitoring

Baseline hashing and change events for files, directories and registry keys — the FIM control auditors ask for, from the same agent.

04

Syslog

RFC3164 and RFC5424 over UDP, TCP and TLS, with octet-counted framing and per-sender overrides for badly behaved appliances.

05

NetFlow

v5, v9 and IPFIX decoding with template caching, flow aggregation and sampling — so flow volume becomes a choice, not a bill.

06

And more, continuously

New sources ship with every release, and this list keeps growing. Need one that isn't here yet? Tell us — customer-driven inputs go to the front of the roadmap.

Pipeline stages

Every byte you don't send is a byte you don't pay for.

Filtering, parsing, enriching and masking all run inside the agent — so noise dies on the endpoint instead of arriving in your SIEM with an invoice attached.

Filter

Drop the events nobody has ever searched, before they cost anything. Predicate rules, sampling and dedup run in the agent — reduction lands on your licence rather than on a processing bill.

predicate rules sampling dedup window
Filter Filter drops events you never want to pay to store — 9.2M directory-object reads become none, and every drop is counted. ×
Action
Drop matching events Keep only matching
Conditions
Match All of the following ⌄
EventID is one of ⌄
4662 — Operation on a directory object ×
4663 — Attempt to access an object ×
e.g. 4662, 4663
×
Type a value and press Enter.
ProcessName is ⌄ e.g. Security ×
+ Add condition
Drop where EventID in 4662, 4663
Paste a sample event
Test with a sample
← Filter Cancel Add rule

What edge processing takes off the bill

Filtering, aggregation and routing happen before delivery, so reduction lands on your licence — not on a processing invoice.

Daily volume collected800 GB/day
Reduced at the edge55%
Effective cost per GB ingested£180 / GB / yr
Annual ingest avoided
£79k
Delivered to Splunk360 GB/day
Dropped or aggregated440 GB/day
Processing surchargeNone
SIEM integrations

Collect once. Send anywhere.

Each platform is supported natively, the way it expects to receive data, so you deploy DPLens once and decide where the data goes afterwards — one platform, several at the same time, or a different one next year. Adding or switching a destination is a settings change, not another rollout across your estate, and no vendor gets to own your data.

S2S & HEC supported natively no vendor lock-in TLS 1.3 reduce noise and cost migrate without re-deploying

New destinations ship continuously — if the platform you need isn't listed yet, it is likely already on the roadmap. Ask us.

Supported destinations
DPLens
DPLens
collect filter · mask route
Splunk
Securonix
Devo
IBM QRadar
Secureworks Taegis
Object store / OTLP archive
SECURITY BY DESIGN

Every design decision in DPLens started with a security question.

Security isn't just an after thought but a core guiding principle at the heart of everything we do. You can deploy DPLens safetly knowing we take the security of our solution and your systems seriously!

Single static file, no runtime

One signed binary. No JVM, no Python, no interpreter, no plugin loader, no dynamic code path an attacker can reach. 

Small, published SBOM

Minimal direct dependencies, SBOM and provenance attestation shipped with every release. Your CVE triage takes minutes, not a quarter.

Memory safe

Written in a memory-safe language with no unsafe parsing paths. The whole class of overflow bugs in log parsers is off the table.

Runs on your infrastructure

No call-home, no vendor control plane, no data leaving a boundary you did not define. Air-gapped installs are supported by default.

Tamper-evident auditing

Config changes, masking decisions and drops are recorded in a hash-chained, signed audit log. Breaks in the chain are detectable, not deniable.

Split-privilege web UI

The UI is a separate unprivileged child process, with no read access to collected data. Compromising it doesn't compromise your system. 

Compliance & regulation

Evidence, not assertions.

Collection completeness, integrity monitoring, data minimisation and residency are all compliance controls that are audited. DPLens produces the artefacts that close them.

Framework
Requirement
How DPLens meets it
PCI DSS 4.0
10.2–10.5 audit logging and log integrity; 11.5 change detection
Guaranteed-delivery queues with indexer ack, FIM inputs, hash-chained agent audit trail, PAN masking before egress
GDPR
Art. 5 minimisation; Art. 32 security of processing; transfer limits
Field-level masking and hashing at source, drop rules before transport, processing stays inside your region
DORA / NIS2
ICT resilience, third-party concentration risk, incident reconstruction
Vendor-agnostic and dual delivery, disk-backed buffering through outages, no external dependency to collect
HIPAA
§164.312 audit controls and integrity of ePHI
Deterministic PHI redaction rules with masking decisions logged, TLS 1.3 mutual auth end to end
ISO 27001 / SOC 2
A.8.15 logging, A.8.16 monitoring, change management evidence
Config as code with signed history, per-source collection health metrics, exportable coverage reports

Empower your SOC team with the signal they need.

Drop the noise before it reaches your pocket and let analysts see the events that matter instead of wading through them. No vendor lock-in with predictable pricing.

Contact us