Splunk integration

Send Windows logs to Splunk over cooked S2S or HEC, filtered before they count.

DPLens speaks the protocol Splunk forwarders use to reach indexers, and the HTTP Event Collector. Keep your indexes and sourcetypes, drop the noise on the Windows host, and ride out an indexer outage on a disk cache.

  • Cooked S2S on 9997
  • HEC on 8088
  • Indexer pool
  • Optional indexer acknowledgement

In short

DPLens integrates natively with Splunk: it sends Windows logs over cooked S2S to a pool of indexers on 9997, or to the HTTP Event Collector on 8088 with the token stored securely on the machine. Index and sourcetype are set per destination and per source, so existing searches keep working, and filtering runs on the host before anything is sent.

Choosing

Should I use S2S or HEC?

S2S when you deliver to indexers and want a load-balanced pool; HEC when your platform exposes a collector endpoint and authenticates with a token.

The two Splunk destination types in DPLens 1.0
SettingCooked S2SHEC
What it isThe protocol Splunk forwarders use to talk to an indexer or heavy forwarderThe HTTP Event Collector
Conventional port99978088
Transport securityTLS, to match your indexers' receiving portHTTPS
AuthenticationMutual TLS, if your indexers require a client certificateHEC token, stored securely; mutual TLS optional
Several receiversPool of indexers or ordered failover listPool of receivers or ordered failover list
Indexer acknowledgementOptionalOptional; enable acknowledgement on the token

Cooked S2S

Deliver to a pool of indexers on 9997

A pool of indexers. List your indexers and traffic rotates across all of them. An indexer that stops accepting is taken out of rotation until it is healthy again, and if every indexer is unavailable, events queue in the disk cache until one returns. For a strict order instead, give an ordered failover list.

TLS, as with the Universal Forwarder. Turn TLS on to match an indexer receiving port configured for it. Certificates are validated against the Windows trust store or a CA you supply, and mutual TLS is available if your indexers ask for a client certificate.

Indexer acknowledgement. Turn it on and an event counts as delivered only once the indexer confirms it. Events the indexer has not confirmed are re-sent, and every re-send is counted.

HTTP Event Collector

Deliver to HEC on 8088 with token authentication

Give DPLens the HEC endpoint and token. The token is stored securely on the machine, so the same configuration can be rolled out to every host with DPLens Manager.

The event endpoint takes batched, structured events; the raw endpoint lets Splunk parse each record itself. HEC destinations also take a pool of receivers or a failover list, and indexer acknowledgement once it is enabled on the token. A rejected token shows as a named fault on the destination, so it is quick to spot and fix.

Index and sourcetype

Will events land where my searches look?

Yes, when you match the index and sourcetype your platform already receives. Both destination types set index, host, source and sourcetype, each as a fixed value or taken from a field in the event, and each can be overridden per source, so one destination can put Windows events, IIS logs and relayed firewall syslog into different indexes. Windows events can be sent in the familiar classic form or as event XML, to suit the sourcetype your searches use.

Match what your searches and dashboards expect today and they keep working unchanged after you switch.

Replacing the Universal Forwarder

Run alongside, compare, then switch

Configure DPLens alongside the Splunk Universal Forwarder (UF), delivering to the same indexers with the same index and sourcetype, compare what arrives, then remove the UF. The walk-through, the UF settings map and how DPLens cuts ingest are on Splunk Universal Forwarder replacement; see also DPLens vs the Universal Forwarder.

DPLens Manager, included in every subscription, gives you central configuration, fleet health monitoring, and deployment and upgrades across every Windows host while you switch over. It is self-hosted and air-gap capable.

Secure by design

An agent you can defend in a security review.

Signed and verifiableEvery release is signed and ships with checksums and a software bill of materials, so you can verify it before it reaches a server.
Nothing calls homeNo telemetry, no licence server and no automatic updates. Your data goes only where you send it.
Secure engineeringBuilt and tested to modern secure-development practice, for software that runs on your most sensitive servers.
Least privilegeRuns with only the access it needs, with administration kept apart from collection.

FAQ

Questions Splunk admins ask

Does DPLens need a heavy forwarder in front of Splunk?

No. The S2S destination delivers to a cooked S2S receiver on an indexer or a heavy forwarder, whichever you point it at.

Does indexer acknowledgement guarantee delivery?

It changes when an event counts as delivered: only once the indexer confirms it. Without it, events still queue in the disk cache whenever the indexers are unreachable, and nothing is dropped silently.

How much Splunk ingest can it save?

It depends on your sources and detections. Model your own numbers in the savings calculator. DPLens itself is priced per agent and per network source, not per GB: see the licensing model.

Splunk is a trademark of Splunk LLC. DPLens is not affiliated with or endorsed by Splunk. The names are used here only to say what DPLens interoperates with.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.