Integrations

SIEM integrations: deliver Windows logs to Splunk, or to any SIEM that speaks syslog or JSON.

DPLens has five receiver types: syslog, Snare, NDJSON, Splunk and OpenTelemetry (OTLP over HTTP). Pick the one your SIEM or pipeline already accepts; syslog, Snare, NDJSON and Splunk destinations each take TLS, a disk cache and a failover address.

  • Splunk S2S and HEC
  • RFC 5424 and RFC 3164 syslog
  • Snare
  • NDJSON
  • OpenTelemetry (OTLP/HTTP)
  • UDP, TCP or TLS

In short

DPLens integrates natively with Splunk (cooked S2S and HEC), sends OTLP over HTTP to an OpenTelemetry Collector or any OTLP endpoint, and works with any SIEM that accepts syslog, Snare-format or JSON lines, including IBM QRadar, Securonix, Devo and Secureworks Taegis through their standard inputs. Over TCP and TLS, syslog, Snare, NDJSON and Splunk destinations each get their own disk cache, an ordered failover list and counted losses, so an outage queues events instead of discarding them.

Receiver types

Which receiver type should I choose?

The one your SIEM already accepts. DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows; its destination wizard starts from a receiver preset that fills in transport, port and format. All ports are configurable.

DPLens 1.0 receiver types, formats, transports and default ports
Receiver typeFormatTransportDefault port
SyslogRFC 5424 or RFC 3164TLS, TCP or UDP6514 TLS (modern preset); 514 UDP (legacy preset)
SnareSnare tab-separated fields, on their own or inside an RFC 3164 lineTLS, TCP or UDP514 TCP
NDJSONOne JSON object per line; the default formatTLS, TCP or UDP2514 TCP
Splunk S2SCooked S2S, the protocol Splunk forwarders useTCP or TLS, to a pool of indexers9997
Splunk HECHTTP Event Collector, event or raw endpointHTTPS8088
OpenTelemetryOTLP log records, protobuf encodingOTLP over HTTP4318

One more format, raw, relays the original record unwrapped, for example syslog that DPLens received from other devices. Over TCP and TLS, syslog, Snare, NDJSON and Splunk destinations each get their own disk cache, automatic reconnection and an ordered failover list, and Splunk destinations can add indexer acknowledgement. Choose TCP or TLS for reliable, counted delivery; UDP is there for receivers that need it.

Several destinations

Can I send to two SIEMs at once?

Yes. Fan-out sends the same events to more than one place; failover sends them to one place, with somewhere to go when it is down. You can use both.

01

Fan-out

One pipeline can deliver to several destinations at once, each receiving the same processed events from its own queue. That is the shape for a SIEM migration (old and new in parallel, then remove the old) or a hot SIEM plus a cheaper archive.

02

Failover

Give a destination an ordered list of addresses. DPLens moves to the next when the current one stops accepting, and moves back once the primary is healthy again. Splunk destinations can instead spread traffic across a pool of indexers.

Every destination on a pipeline receives the same filtered events, so plan the filters for the pair, or migrate source by source. See SIEM cost reduction for what to filter.

Secure by design

An agent you can defend in a security review.

Signed and verifiableEvery release is signed and ships with checksums and a software bill of materials, so you can verify it before it reaches a server.
Nothing calls homeNo telemetry, no licence server and no automatic updates. Your data goes only where you send it.
Secure engineeringBuilt and tested to modern secure-development practice, for software that runs on your most sensitive servers.
Least privilegeRuns with only the access it needs, with administration kept apart from collection.

FAQ

Questions buyers ask

Which SIEMs does DPLens support natively?

Splunk, through two dedicated destination types: cooked S2S and HEC. Every other SIEM is reached through the standard receiver type it already accepts: syslog, Snare, NDJSON or OpenTelemetry.

Can I send over OpenTelemetry (OTLP)?

Yes. DPLens 1.0 sends OTLP log records over HTTP with protobuf encoding, conventionally on port 4318, to an OpenTelemetry Collector or any OTLP endpoint. See OpenTelemetry.

How do I keep a low-cost archive alongside my SIEM?

Fan out a second copy of the events as NDJSON to a collector you run, which writes to the object store or data lake you choose.

What happens if the SIEM is unreachable?

On TCP and TLS, events queue in the destination's disk cache and are delivered when it returns. Splunk destinations can also wait for indexer acknowledgement. If a cache fills, your chosen policy (pause collection, drop oldest or drop newest) applies and every drop is counted.

Splunk is a trademark of Splunk LLC; IBM QRadar, Securonix, Devo, Secureworks Taegis, Snare and OpenTelemetry are trademarks of their respective owners. DPLens is not affiliated with or endorsed by any of them. The names are used only to say what DPLens interoperates with.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.