Splunk integration
Send Windows logs to Splunk over cooked S2S or HEC, filtered before they count.
DPLens speaks the protocol Splunk forwarders use to reach indexers, and the HTTP Event Collector. Keep your indexes and sourcetypes, drop the noise on the Windows host, and ride out an indexer outage on a disk cache.
- Cooked S2S on 9997
- HEC on 8088
- Indexer pool
- Optional indexer acknowledgement
In short
DPLens integrates natively with Splunk: it sends Windows logs over cooked S2S to a pool of indexers on 9997, or to the HTTP Event Collector on 8088 with the token stored securely on the machine. Index and sourcetype are set per destination and per source, so existing searches keep working, and filtering runs on the host before anything is sent.
Choosing
Should I use S2S or HEC?
S2S when you deliver to indexers and want a load-balanced pool; HEC when your platform exposes a collector endpoint and authenticates with a token.
| Setting | Cooked S2S | HEC |
|---|---|---|
| What it is | The protocol Splunk forwarders use to talk to an indexer or heavy forwarder | The HTTP Event Collector |
| Conventional port | 9997 | 8088 |
| Transport security | TLS, to match your indexers' receiving port | HTTPS |
| Authentication | Mutual TLS, if your indexers require a client certificate | HEC token, stored securely; mutual TLS optional |
| Several receivers | Pool of indexers or ordered failover list | Pool of receivers or ordered failover list |
| Indexer acknowledgement | Optional | Optional; enable acknowledgement on the token |
Cooked S2S
Deliver to a pool of indexers on 9997
A pool of indexers. List your indexers and traffic rotates across all of them. An indexer that stops accepting is taken out of rotation until it is healthy again, and if every indexer is unavailable, events queue in the disk cache until one returns. For a strict order instead, give an ordered failover list.
TLS, as with the Universal Forwarder. Turn TLS on to match an indexer receiving port configured for it. Certificates are validated against the Windows trust store or a CA you supply, and mutual TLS is available if your indexers ask for a client certificate.
Indexer acknowledgement. Turn it on and an event counts as delivered only once the indexer confirms it. Events the indexer has not confirmed are re-sent, and every re-send is counted.
HTTP Event Collector
Deliver to HEC on 8088 with token authentication
Give DPLens the HEC endpoint and token. The token is stored securely on the machine, so the same configuration can be rolled out to every host with DPLens Manager.
The event endpoint takes batched, structured events; the raw endpoint lets Splunk parse each record itself. HEC destinations also take a pool of receivers or a failover list, and indexer acknowledgement once it is enabled on the token. A rejected token shows as a named fault on the destination, so it is quick to spot and fix.
Index and sourcetype
Will events land where my searches look?
Yes, when you match the index and sourcetype your platform already receives. Both destination types set index, host, source and sourcetype, each as a fixed value or taken from a field in the event, and each can be overridden per source, so one destination can put Windows events, IIS logs and relayed firewall syslog into different indexes. Windows events can be sent in the familiar classic form or as event XML, to suit the sourcetype your searches use.
Match what your searches and dashboards expect today and they keep working unchanged after you switch.
Replacing the Universal Forwarder
Run alongside, compare, then switch
Configure DPLens alongside the Splunk Universal Forwarder (UF), delivering to the same indexers with the same index and sourcetype, compare what arrives, then remove the UF. The walk-through, the UF settings map and how DPLens cuts ingest are on Splunk Universal Forwarder replacement; see also DPLens vs the Universal Forwarder.
DPLens Manager, included in every subscription, gives you central configuration, fleet health monitoring, and deployment and upgrades across every Windows host while you switch over. It is self-hosted and air-gap capable.
Secure by design
An agent you can defend in a security review.
FAQ
Questions Splunk admins ask
Does DPLens need a heavy forwarder in front of Splunk?
No. The S2S destination delivers to a cooked S2S receiver on an indexer or a heavy forwarder, whichever you point it at.
Does indexer acknowledgement guarantee delivery?
It changes when an event counts as delivered: only once the indexer confirms it. Without it, events still queue in the disk cache whenever the indexers are unreachable, and nothing is dropped silently.
How much Splunk ingest can it save?
It depends on your sources and detections. Model your own numbers in the savings calculator. DPLens itself is priced per agent and per network source, not per GB: see the licensing model.
See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.