Integrations
SIEM integrations: deliver Windows logs to Splunk, or to any SIEM that speaks syslog or JSON.
DPLens has five receiver types: syslog, Snare, NDJSON, Splunk and OpenTelemetry (OTLP over HTTP). Pick the one your SIEM or pipeline already accepts; syslog, Snare, NDJSON and Splunk destinations each take TLS, a disk cache and a failover address.
- Splunk S2S and HEC
- RFC 5424 and RFC 3164 syslog
- Snare
- NDJSON
- OpenTelemetry (OTLP/HTTP)
- UDP, TCP or TLS
In short
DPLens integrates natively with Splunk (cooked S2S and HEC), sends OTLP over HTTP to an OpenTelemetry Collector or any OTLP endpoint, and works with any SIEM that accepts syslog, Snare-format or JSON lines, including IBM QRadar, Securonix, Devo and Secureworks Taegis through their standard inputs. Over TCP and TLS, syslog, Snare, NDJSON and Splunk destinations each get their own disk cache, an ordered failover list and counted losses, so an outage queues events instead of discarding them.
Receiver types
Which receiver type should I choose?
The one your SIEM already accepts. DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows; its destination wizard starts from a receiver preset that fills in transport, port and format. All ports are configurable.
| Receiver type | Format | Transport | Default port |
|---|---|---|---|
| Syslog | RFC 5424 or RFC 3164 | TLS, TCP or UDP | 6514 TLS (modern preset); 514 UDP (legacy preset) |
| Snare | Snare tab-separated fields, on their own or inside an RFC 3164 line | TLS, TCP or UDP | 514 TCP |
| NDJSON | One JSON object per line; the default format | TLS, TCP or UDP | 2514 TCP |
| Splunk S2S | Cooked S2S, the protocol Splunk forwarders use | TCP or TLS, to a pool of indexers | 9997 |
| Splunk HEC | HTTP Event Collector, event or raw endpoint | HTTPS | 8088 |
| OpenTelemetry | OTLP log records, protobuf encoding | OTLP over HTTP | 4318 |
One more format, raw, relays the original record unwrapped, for example syslog that DPLens received from other devices. Over TCP and TLS, syslog, Snare, NDJSON and Splunk destinations each get their own disk cache, automatic reconnection and an ordered failover list, and Splunk destinations can add indexer acknowledgement. Choose TCP or TLS for reliable, counted delivery; UDP is there for receivers that need it.
By destination
Integration guides
Each guide says which receiver type to choose, what to configure on each side, and how delivery is protected along the way.
Native
Splunk
Cooked S2S to a pool of indexers on 9997, or HEC on 8088 with the token stored securely. Index, host, source and sourcetype set per source.
Read more →syslog
IBM QRadar
RFC 5424 syslog over TLS, or Snare records if your log source already parses them. Filtered at the source to save events per second.
Read more →syslog · NDJSON
Securonix
Syslog to the collection point your Securonix deployment uses, or JSON lines where that ingestion path accepts them.
Read more →syslog · NDJSON
Devo
Syslog over TLS to your Devo collection point, with mutual TLS if the endpoint asks for a client certificate.
Read more →syslog
Secureworks Taegis
Syslog from Windows servers to a Taegis collector, with disk-backed delivery between the agent and the collector.
Read more →Any receiver
Syslog, Snare and NDJSON
rsyslog, syslog-ng, existing Snare receivers, and JSON collectors in front of a data lake.
Read more →OTLP/HTTP
OpenTelemetry
OTLP over HTTP on 4318 to an OpenTelemetry Collector or any OTLP endpoint, so Windows logs join a vendor-neutral pipeline.
Read more →Using another platform? Most SIEMs and log stores take syslog, Snare, JSON lines or OTLP. Tell us what you send to today and how it ingests, and we will help you choose the right receiver type.
Several destinations
Can I send to two SIEMs at once?
Yes. Fan-out sends the same events to more than one place; failover sends them to one place, with somewhere to go when it is down. You can use both.
01
Fan-out
One pipeline can deliver to several destinations at once, each receiving the same processed events from its own queue. That is the shape for a SIEM migration (old and new in parallel, then remove the old) or a hot SIEM plus a cheaper archive.
02
Failover
Give a destination an ordered list of addresses. DPLens moves to the next when the current one stops accepting, and moves back once the primary is healthy again. Splunk destinations can instead spread traffic across a pool of indexers.
Every destination on a pipeline receives the same filtered events, so plan the filters for the pair, or migrate source by source. See SIEM cost reduction for what to filter.
Secure by design
An agent you can defend in a security review.
FAQ
Questions buyers ask
Which SIEMs does DPLens support natively?
Splunk, through two dedicated destination types: cooked S2S and HEC. Every other SIEM is reached through the standard receiver type it already accepts: syslog, Snare, NDJSON or OpenTelemetry.
Can I send over OpenTelemetry (OTLP)?
Yes. DPLens 1.0 sends OTLP log records over HTTP with protobuf encoding, conventionally on port 4318, to an OpenTelemetry Collector or any OTLP endpoint. See OpenTelemetry.
How do I keep a low-cost archive alongside my SIEM?
Fan out a second copy of the events as NDJSON to a collector you run, which writes to the object store or data lake you choose.
What happens if the SIEM is unreachable?
On TCP and TLS, events queue in the destination's disk cache and are delivered when it returns. Splunk destinations can also wait for indexer acknowledgement. If a cache fills, your chosen policy (pause collection, drop oldest or drop newest) applies and every drop is counted.
See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.