Everything you need from your servers, and the devices around it.
One platform and complete control across every input. Single install, no forwarder sprawl, no vendor lock in and no central resource drain.
Windows Event Log
Native subscription to Security, System, Sysmon and any custom channel. XPath selection, bookmark checkpointing, rendered or raw XML.
Log files
Glob tailing with rotation, truncation and multiline handling. Positions survive restart; back-pressure never loses a line.
File integrity monitoring
Baseline hashing and change events for files, directories and registry keys — the FIM control auditors ask for, from the same agent.
Syslog
RFC3164 and RFC5424 over UDP, TCP and TLS, with octet-counted framing and per-sender overrides for badly behaved appliances.
NetFlow
v5, v9 and IPFIX decoding with template caching, flow aggregation and sampling — so flow volume becomes a choice, not a bill.
And more, continuously
New sources ship with every release, and this list keeps growing. Need one that isn't here yet? Tell us — customer-driven inputs go to the front of the roadmap.
Every byte you don't send is a byte you don't pay for.
Filtering, parsing, enriching and masking all run inside the agent — so noise dies on the endpoint instead of arriving in your SIEM with an invoice attached.
Filter
Drop the events nobody has ever searched, before they cost anything. Predicate rules, sampling and dedup run in the agent — reduction lands on your licence rather than on a processing bill.
What edge processing takes off the bill
Filtering, aggregation and routing happen before delivery, so reduction lands on your licence — not on a processing invoice.
Collect once. Send anywhere.
Each platform is supported natively, the way it expects to receive data, so you deploy DPLens once and decide where the data goes afterwards — one platform, several at the same time, or a different one next year. Adding or switching a destination is a settings change, not another rollout across your estate, and no vendor gets to own your data.
New destinations ship continuously — if the platform you need isn't listed yet, it is likely already on the roadmap. Ask us.
Every design decision in DPLens started with a security question.
Security isn't just an after thought but a core guiding principle at the heart of everything we do. You can deploy DPLens safetly knowing we take the security of our solution and your systems seriously!
Single static file, no runtime
One signed binary. No JVM, no Python, no interpreter, no plugin loader, no dynamic code path an attacker can reach.
Small, published SBOM
Minimal direct dependencies, SBOM and provenance attestation shipped with every release. Your CVE triage takes minutes, not a quarter.
Memory safe
Written in a memory-safe language with no unsafe parsing paths. The whole class of overflow bugs in log parsers is off the table.
Runs on your infrastructure
No call-home, no vendor control plane, no data leaving a boundary you did not define. Air-gapped installs are supported by default.
Tamper-evident auditing
Config changes, masking decisions and drops are recorded in a hash-chained, signed audit log. Breaks in the chain are detectable, not deniable.
Split-privilege web UI
The UI is a separate unprivileged child process, with no read access to collected data. Compromising it doesn't compromise your system.
Evidence, not assertions.
Collection completeness, integrity monitoring, data minimisation and residency are all compliance controls that are audited. DPLens produces the artefacts that close them.
Empower your SOC team with the signal they need.
Drop the noise before it reaches your pocket and let analysts see the events that matter instead of wading through them. No vendor lock-in with predictable pricing.