Devo

Send Windows event logs to Devo over syslog, smaller and encrypted.

DPLens delivers Windows Event Log data as syslog over TLS to the collection point your Devo domain receives from, filters and masks it on the Windows host, and queues it on disk if that collection point is unreachable.

  • RFC 5424 syslog
  • TLS and mutual TLS
  • NDJSON
  • Disk cache

In short

DPLens sends Windows event logs to Devo as standard RFC 5424 syslog over TLS, using mutual TLS where the collection point asks for a client certificate. How events are classified and parsed is decided on the Devo side, so agree that with your Devo administrator first; DPLens's job is to deliver a smaller, cleaner, encrypted stream.

Which receiver type

Which format should I send to Devo?

DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. RFC 5424 syslog over TLS is the usual choice: syslog is the most widely accepted way into a SIEM, and RFC 5424 carries a precise timestamp with an offset. RFC 3164 is there for receivers that expect it. Choose NDJSON instead if your collection point accepts JSON lines and has a parser for them; it keeps parsed and enriched values as named fields.

Classification happens on the Devo side

Devo decides where an event lands and how it is parsed. Before you roll out, agree with your Devo administrator how Windows events from DPLens will be identified. DPLens can help: you set the application name and the hostname in the syslog header, so if the collection point keys on either, you control the value. Send a test event and confirm it arrives where you expect.

Mutual TLS

If the endpoint requires the agent to present a certificate, give DPLens the client certificate and key. Both are stored securely on the machine, so the same configuration can be rolled out to every host with DPLens Manager.

DPLens destination settings for Devo
SettingSuggested value
TransportTLS
AddressYour collection point's host and TLS port
FormatRFC 5424 syslog
FramingOctet-counted where the receiver accepts it, otherwise newline
Application nameThe value your Devo administrator agrees
CA certificateThe endpoint's issuing CA, or the Windows trust store
Client certificate and keyWhere the endpoint asks for mutual TLS
Disk cache sizeEnough for the outage you want to ride out

Ingest

Send less to a cloud SIEM

Where your SIEM costs scale with what you send, the cheapest event is the one that never leaves the host. Every drop and mask is counted and attributed to its rule; see SIEM cost reduction and log masking.

01

Exclude at the source

Event IDs no query or alert uses can be excluded on the Windows Event Log source, so they are never read.

02

Collapse repeats

Aggregate repeated failures by user and address into one event with a count.

03

Mask before it leaves

Masking runs before the disk cache and before sending, so a value a rule rewrites never leaves the machine.

04

Keep a full copy elsewhere

Fan out the same events to Devo and to an NDJSON collector you run for archive. See syslog, Snare and NDJSON.

Rolling out

Configure once, deploy to every Windows server

DPLens Manager, included in every subscription, gives you central configuration, fleet health monitoring, and deployment and upgrades for every agent that feeds Devo. It is self-hosted and air-gap capable.

Secure by design

An agent you can defend in a security review.

Signed and verifiableEvery release is signed and ships with checksums and a software bill of materials, so you can verify it before it reaches a server.
Nothing calls homeNo telemetry, no licence server and no automatic updates. Your data goes only where you send it.
Secure engineeringBuilt and tested to modern secure-development practice, for software that runs on your most sensitive servers.
Least privilegeRuns with only the access it needs, with administration kept apart from collection.

FAQ

Questions Devo teams ask

How does DPLens connect to Devo?

Through Devo's own collection points. DPLens sends standard RFC 5424 syslog, or NDJSON, over TLS, and Devo classifies and parses it as your administrator configures.

Can DPLens present a client certificate?

Yes. Mutual TLS is supported on TLS destinations, with the client certificate and key stored securely on the machine.

How do I check what Devo will receive?

Send a test event from a source's row menu and watch Live stream with the Devo destination selected. You see the exact bytes sent, including the header fields and anything your masking rules rewrote.

Devo is a trademark of its owner. DPLens is not affiliated with or endorsed by Devo. The name is used here only to say what DPLens interoperates with.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.