Secureworks Taegis
Forward Windows logs to a Secureworks Taegis collector over syslog.
DPLens sends Windows Event Log data from your servers to the syslog input of a Taegis collector, with a disk cache between the agent and the collector so a restart or outage does not cost you events.
- RFC 5424 syslog
- TCP or TLS
- Disk cache and failover
In short
DPLens forwards Windows logs to Secureworks Taegis as standard syslog: install it on the Windows servers you want covered and point it at your Taegis collector's syslog input. Confirm with Secureworks which formats your collector normalises before you roll out.
Which receiver type
How should I send Windows logs to a Taegis collector?
DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. Choose syslog: RFC 5424 for its precise timestamp with an offset, or RFC 3164 where the collector expects it. The syslog guide covers framing and header fields.
Use TLS where the collector's syslog input supports it, or TCP on a network segment you control. On TCP and TLS, events queue on disk while the collector is unreachable and are delivered when it returns, and every event is counted.
Check what the collector normalises
Ask Secureworks which Windows event formats your collector parses, whether it expects the Windows message text (if so, turn on message rendering for the Windows Event Log source), and which detections those events feed. Send a test event and confirm it arrives normalised before you roll out.
| Setting | Suggested value |
|---|---|
| Transport | TLS where the collector supports it, otherwise TCP |
| Address | The collector's address and syslog port |
| Format | RFC 5424 syslog |
| Framing | Match the collector: octet-counted or newline |
| Failover | A second collector, if you run one |
| Hostname | This machine's name (the default) |
| When the cache fills | Pause collection, so Windows holds the events until the collector catches up |
Filtering
Filter for detection, not just for volume
With a managed detection platform, the events that matter most are the ones its detections read. Filter with that list in hand. DPLens counts every drop and attributes it to the rule that made it, so you can show what was excluded. See noisy Windows Security Event IDs.
01
Keep the core security events
Logons and failures, process creation, account and group changes and service installs are the backbone of most Windows detections.
02
Exclude provable noise at the source
Event IDs nothing reads can be excluded on the source, where they are never read at all.
03
Add channels deliberately
One source can read several channels, such as Security, System, Sysmon and PowerShell, in step. Add them when the collector parses them; see Windows Event Log collection.
Rolling out
Configure once, deploy to every Windows server
DPLens Manager, included in every subscription, gives you central configuration, fleet health monitoring, and deployment and upgrades for every agent that feeds your Taegis collectors. It is self-hosted and air-gap capable.
Secure by design
An agent you can defend in a security review.
FAQ
Questions Taegis customers ask
How does DPLens connect to Taegis?
Through the collector's syslog input. DPLens sends standard RFC 5424 syslog from each Windows server to your Taegis collector, over TLS or TCP.
What does DPLens add to Taegis?
The Windows event logs, log files and file integrity events you want in Taegis from your servers, filtered and masked on the host and delivered with a disk cache and failover.
What happens if the collector restarts?
On TCP or TLS, events queue in the destination's disk cache and are delivered when the collector accepts again, or DPLens moves to a failover collector. If the cache fills, your chosen policy applies and every drop is counted.
See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.