Secureworks Taegis

Forward Windows logs to a Secureworks Taegis collector over syslog.

DPLens sends Windows Event Log data from your servers to the syslog input of a Taegis collector, with a disk cache between the agent and the collector so a restart or outage does not cost you events.

  • RFC 5424 syslog
  • TCP or TLS
  • Disk cache and failover

In short

DPLens forwards Windows logs to Secureworks Taegis as standard syslog: install it on the Windows servers you want covered and point it at your Taegis collector's syslog input. Confirm with Secureworks which formats your collector normalises before you roll out.

Which receiver type

How should I send Windows logs to a Taegis collector?

DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. Choose syslog: RFC 5424 for its precise timestamp with an offset, or RFC 3164 where the collector expects it. The syslog guide covers framing and header fields.

Use TLS where the collector's syslog input supports it, or TCP on a network segment you control. On TCP and TLS, events queue on disk while the collector is unreachable and are delivered when it returns, and every event is counted.

Check what the collector normalises

Ask Secureworks which Windows event formats your collector parses, whether it expects the Windows message text (if so, turn on message rendering for the Windows Event Log source), and which detections those events feed. Send a test event and confirm it arrives normalised before you roll out.

DPLens destination settings for a Taegis collector
SettingSuggested value
TransportTLS where the collector supports it, otherwise TCP
AddressThe collector's address and syslog port
FormatRFC 5424 syslog
FramingMatch the collector: octet-counted or newline
FailoverA second collector, if you run one
HostnameThis machine's name (the default)
When the cache fillsPause collection, so Windows holds the events until the collector catches up

Filtering

Filter for detection, not just for volume

With a managed detection platform, the events that matter most are the ones its detections read. Filter with that list in hand. DPLens counts every drop and attributes it to the rule that made it, so you can show what was excluded. See noisy Windows Security Event IDs.

01

Keep the core security events

Logons and failures, process creation, account and group changes and service installs are the backbone of most Windows detections.

02

Exclude provable noise at the source

Event IDs nothing reads can be excluded on the source, where they are never read at all.

03

Add channels deliberately

One source can read several channels, such as Security, System, Sysmon and PowerShell, in step. Add them when the collector parses them; see Windows Event Log collection.

Rolling out

Configure once, deploy to every Windows server

DPLens Manager, included in every subscription, gives you central configuration, fleet health monitoring, and deployment and upgrades for every agent that feeds your Taegis collectors. It is self-hosted and air-gap capable.

Secure by design

An agent you can defend in a security review.

Signed and verifiableEvery release is signed and ships with checksums and a software bill of materials, so you can verify it before it reaches a server.
Nothing calls homeNo telemetry, no licence server and no automatic updates. Your data goes only where you send it.
Secure engineeringBuilt and tested to modern secure-development practice, for software that runs on your most sensitive servers.
Least privilegeRuns with only the access it needs, with administration kept apart from collection.

FAQ

Questions Taegis customers ask

How does DPLens connect to Taegis?

Through the collector's syslog input. DPLens sends standard RFC 5424 syslog from each Windows server to your Taegis collector, over TLS or TCP.

What does DPLens add to Taegis?

The Windows event logs, log files and file integrity events you want in Taegis from your servers, filtered and masked on the host and delivered with a disk cache and failover.

What happens if the collector restarts?

On TCP or TLS, events queue in the destination's disk cache and are delivered when the collector accepts again, or DPLens moves to a failover collector. If the cache fills, your chosen policy applies and every drop is counted.

Secureworks and Taegis are trademarks of their respective owners. DPLens is not affiliated with or endorsed by them. The names are used here only to say what DPLens interoperates with.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.