Devo
Send Windows event logs to Devo over syslog, smaller and encrypted.
DPLens delivers Windows Event Log data as syslog over TLS to the collection point your Devo domain receives from, filters and masks it on the Windows host, and queues it on disk if that collection point is unreachable.
- RFC 5424 syslog
- TLS and mutual TLS
- NDJSON
- Disk cache
In short
DPLens sends Windows event logs to Devo as standard RFC 5424 syslog over TLS, using mutual TLS where the collection point asks for a client certificate. How events are classified and parsed is decided on the Devo side, so agree that with your Devo administrator first; DPLens's job is to deliver a smaller, cleaner, encrypted stream.
Which receiver type
Which format should I send to Devo?
DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. RFC 5424 syslog over TLS is the usual choice: syslog is the most widely accepted way into a SIEM, and RFC 5424 carries a precise timestamp with an offset. RFC 3164 is there for receivers that expect it. Choose NDJSON instead if your collection point accepts JSON lines and has a parser for them; it keeps parsed and enriched values as named fields.
Classification happens on the Devo side
Devo decides where an event lands and how it is parsed. Before you roll out, agree with your Devo administrator how Windows events from DPLens will be identified. DPLens can help: you set the application name and the hostname in the syslog header, so if the collection point keys on either, you control the value. Send a test event and confirm it arrives where you expect.
Mutual TLS
If the endpoint requires the agent to present a certificate, give DPLens the client certificate and key. Both are stored securely on the machine, so the same configuration can be rolled out to every host with DPLens Manager.
| Setting | Suggested value |
|---|---|
| Transport | TLS |
| Address | Your collection point's host and TLS port |
| Format | RFC 5424 syslog |
| Framing | Octet-counted where the receiver accepts it, otherwise newline |
| Application name | The value your Devo administrator agrees |
| CA certificate | The endpoint's issuing CA, or the Windows trust store |
| Client certificate and key | Where the endpoint asks for mutual TLS |
| Disk cache size | Enough for the outage you want to ride out |
Ingest
Send less to a cloud SIEM
Where your SIEM costs scale with what you send, the cheapest event is the one that never leaves the host. Every drop and mask is counted and attributed to its rule; see SIEM cost reduction and log masking.
01
Exclude at the source
Event IDs no query or alert uses can be excluded on the Windows Event Log source, so they are never read.
02
Collapse repeats
Aggregate repeated failures by user and address into one event with a count.
03
Mask before it leaves
Masking runs before the disk cache and before sending, so a value a rule rewrites never leaves the machine.
04
Keep a full copy elsewhere
Fan out the same events to Devo and to an NDJSON collector you run for archive. See syslog, Snare and NDJSON.
Rolling out
Configure once, deploy to every Windows server
DPLens Manager, included in every subscription, gives you central configuration, fleet health monitoring, and deployment and upgrades for every agent that feeds Devo. It is self-hosted and air-gap capable.
Secure by design
An agent you can defend in a security review.
FAQ
Questions Devo teams ask
How does DPLens connect to Devo?
Through Devo's own collection points. DPLens sends standard RFC 5424 syslog, or NDJSON, over TLS, and Devo classifies and parses it as your administrator configures.
Can DPLens present a client certificate?
Yes. Mutual TLS is supported on TLS destinations, with the client certificate and key stored securely on the machine.
How do I check what Devo will receive?
Send a test event from a source's row menu and watch Live stream with the Devo destination selected. You see the exact bytes sent, including the header fields and anything your masking rules rewrote.
See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.