Securonix

Send Windows logs to Securonix as syslog or JSON, masked and filtered on the host.

DPLens delivers Windows Event Log data to the syslog or JSON-lines input your Securonix deployment collects from, over TLS, with a disk cache that rides out an outage of the collection point.

  • RFC 5424 syslog
  • NDJSON
  • TLS
  • PII masking before send

In short

DPLens sends Windows logs to Securonix through standard inputs: RFC 5424 syslog, or newline-delimited JSON where your collection point has a JSON parser for it. Send over TLS, mask personal data on the Windows host before it leaves, and filter carefully, because behaviour analytics depends on identity events you might otherwise think of as noise.

Which receiver type

Should I send syslog or JSON to Securonix?

DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. RFC 5424 syslog is the safe choice: syslog is the most widely accepted way into a SIEM, and Securonix collection points generally accept it. Confirm with your Securonix team which parser will be applied to Windows events, and whether it expects the rendered message text; if it does, turn on message rendering for the Windows Event Log source.

NDJSON preserves the most. Parsed values, enrichment and normalised field names arrive as named fields rather than being flattened into a message string, which makes parsing on the receiving side simpler. Choose it when your collection point has a JSON-lines input and a parser mapped to the fields DPLens sends. Each record starts with source_id, source_seq, time_event and time_collected, so gaps and duplicates are detectable downstream.

Transport

Use TLS to the collector, or TCP on a network you control; both give disk-cached, counted delivery with failover. The syslog, Snare and NDJSON guide covers formats and framing.

DPLens destination settings for Securonix
SettingSyslogNDJSON
TransportTLSTLS
AddressThe collector's syslog port, usually 6514The collector's JSON input, for example 2514
FormatRFC 5424 syslogNDJSON
FramingOctet-counted, where the collector accepts itNewline
FailoverA second collector, if you have one
CA certificateThe collector's issuing CA, or the Windows trust store

Filtering for behaviour analytics

Cut volume without starving the models

Behaviour analytics builds baselines from identity and access events, so filter for Securonix differently from a rules-only SIEM. Every drop, aggregation and mask DPLens applies is counted and attributed to its rule.

01

Keep identity events whole

Logon, logoff, Kerberos and account-change events feed baselines. Drop machine-account noise (target names ending in $) rather than whole Event IDs.

02

Be careful with aggregation

Aggregation turns many repeats into one event that carries a count. If a policy counts raw events, it will see fewer. Check that the policy can read the count before you collapse anything.

03

Exclude what no policy reads

Event IDs no policy uses are best excluded on the source, where they are never read at all.

04

Pseudonymise, consistently

Keyed-hash masking replaces a value with a consistent pseudonym, so the same input always gives the same output and you can still correlate. If Securonix must resolve identities against HR or directory data, mask other fields, not user names. See log masking and PII redaction.

Rolling out

Configure once, deploy to every Windows server

DPLens Manager, included in every subscription, gives you central configuration, fleet health monitoring, and deployment and upgrades for every agent that feeds Securonix. It is self-hosted and air-gap capable.

Secure by design

An agent you can defend in a security review.

Signed and verifiableEvery release is signed and ships with checksums and a software bill of materials, so you can verify it before it reaches a server.
Nothing calls homeNo telemetry, no licence server and no automatic updates. Your data goes only where you send it.
Secure engineeringBuilt and tested to modern secure-development practice, for software that runs on your most sensitive servers.
Least privilegeRuns with only the access it needs, with administration kept apart from collection.

FAQ

Questions Securonix teams ask

How does DPLens connect to Securonix?

Through standard inputs. DPLens sends RFC 5424 syslog or NDJSON, and Securonix receives it through whichever syslog or JSON input your deployment uses.

Should I choose syslog or NDJSON?

Choose NDJSON if your collection point has a JSON-lines input and a parser for the fields; it keeps everything as named fields. Otherwise choose RFC 5424 syslog over TLS.

Can I mask personal data before it reaches Securonix?

Yes. Masking runs before anything is written to the disk cache or sent, with built-in detectors for card numbers, email addresses, IP addresses, phone numbers, US SSNs and UK National Insurance numbers, plus your own patterns. Keyed hashing pseudonymises values consistently, so you can still correlate on them.

Can I send to Securonix and our current SIEM during a migration?

Yes. One pipeline can deliver the same processed events to several destinations, each with its own queue, so one being down does not hold up the other. See SIEM integrations.

Securonix is a trademark of its owner. DPLens is not affiliated with or endorsed by Securonix. The name is used here only to say what DPLens interoperates with.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.