How it works

A security data pipeline that runs on the Windows host itself.

DPLens collects, reduces, masks and delivers log data on the machine that produced it, and DPLens Manager runs the whole fleet from one place. No vendor cloud sits between your logs and your SIEM.

  • Windows x64
  • Edge log processing
  • Syslog, Snare, NDJSON, Splunk, OpenTelemetry
  • DPLens Manager included

In short

DPLens is a security data pipeline that runs on each Windows host: it collects event logs, log files, file-integrity scans, syslog and NetFlow, reduces and masks them in seven stages, and delivers the result to your SIEM over syslog, Snare, NDJSON or the Splunk protocols, or to an OpenTelemetry Collector over OTLP. Processing happens on the host, so there is no separate processing tier to build, and DPLens Manager, included in every subscription, gives you central configuration, fleet health monitoring, and deployment and upgrades. In our lab benchmark DPLens delivered more than 30× the throughput of the established Windows agents we tested, at about a tenth of the CPU per event.

Architecture

One agent per Windows host, managed centrally

DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. Each machine runs one signed agent as a Windows service. Reduction happens before data leaves the host, so the SIEM only receives what you chose to send.

How data moves through one DPLens agent
Sources (in)Stages (on the host)Destinations (out)
Windows Event Log channels1. FilterSyslog (RFC 5424 or 3164)
Log files (path or wildcard)2. Parse and normaliseSnare
File integrity (scheduled scans)3. Aggregate, then 4. OptimiseNDJSON collector
Syslog receiver (UDP or TCP)5. EnrichSplunk cooked S2S or HTTP Event Collector (HEC)
NetFlow v5 and IPFIX receiver6. Mask, then 7. Rate limitOpenTelemetry (OTLP over HTTP)

01

Self-contained

One signed installer is all a host needs. There is nothing else to install or patch alongside it, and no internet access is required.

02

Configuration as code

Define a configuration once, review it, keep it in source control and apply it across your fleet. Credentials are kept out of it.

03

Rolled out your way

Deploy and upgrade with DPLens Manager, or with the tools you already use: Group Policy, Intune, Configuration Manager or an RMM, plus golden images and VDI. See deployment.

Sources

What it collects

Collection resumes exactly where it stopped after a restart, upgrade or pause, so nothing is read twice or skipped.

DPLens 1.0 sources
SourceWhat it does
Windows Event LogAny number of channels, including Security, Sysmon and your own custom channels. Select events by severity, Event ID, provider or XPath, and backfill history when you need it.
Log filesAny path or wildcard, on local disks or network shares. Rotated files are followed, new matching files are picked up, and UTF-8 and UTF-16 are detected.
File integrityWatches files, folders and wildcards against a baseline, scanning every 15 minutes, hourly or daily. Changes arrive as events.
Syslog receiverReceives RFC 3164 and RFC 5424 syslog over UDP or TCP from firewalls, switches and appliances, from the networks you allow.
NetFlow and IPFIX receiverReceives NetFlow v5 and IPFIX over UDP, and IPFIX over TCP, so flow records go through the same pipeline as your logs.

Each enabled syslog or NetFlow receiver is one network source for pricing, however many devices send to it: one syslog receiver taking events from 500 firewalls is one network source. See pricing.

Pipeline

What happens between collection and delivery?

Seven processing stages, always in this order: filter, parse, aggregate, optimise, enrich, mask, rate limit. Run several pipelines, each delivering to several destinations at once. Every drop, mask, aggregation and failover is counted and attributed to the rule that caused it.

  1. Collect

    Read from the five sources above and select events at the source, the cheapest reduction there is. Example: one source reads Security, System, Application and Sysmon, keeping only the Event IDs you name.

  2. Filter

    Keep or drop events with rules that test values, text, patterns, numbers, lists and network ranges, combined however you need. Example: keep Event IDs 4624, 4625, 4634, 4688 and 4720, and drop those whose target user name ends in $ (machine accounts).

  3. Parse

    Turn raw text into fields from JSON, syslog, delimited, key-value or free-text formats, and normalise Windows security events to CIM or OCSF names. Events that fail to parse are routed and counted, so a format change surfaces straight away.

  4. Aggregate

    Collapse repeats into one representative event carrying the count, grouped by the fields you choose over a time window. Example: failed logons (Event ID 4625) for the same user and address inside 60 seconds become one event.

  5. Optimise

    Remove fields that hold a placeholder rather than a fact, such as an empty value, a dash, "N/A" or a null SID, so every event is smaller without losing information. You choose which values to remove, and the console shows the estimated saving.

  6. Enrich

    Add static tags and host facts such as host name, domain, OS version, local addresses and time zone, plus the machine's public IP if you choose. Example: tag every event with site: lon-dc1 and env: prod.

  7. Mask

    Detect card numbers, email and IP addresses, US SSNs, UK National Insurance numbers, phone numbers or your own pattern, then redact, partially mask, tokenise or hash. Masking happens before anything is stored or sent; every masking decision is counted, and masking-policy changes are recorded in the tamper-evident audit trail. Example: keep only the last four digits of a card number.

  8. Rate limit

    Cap events or bytes per second, with short bursts smoothed out, so one noisy machine cannot exhaust a licence or swamp an indexer. Example: 2,000 events a second with bursts to 4,000. Every shed event is counted.

  9. Deliver

    Encode for the receiver and send it: syslog, Snare, NDJSON and Splunk over UDP, TCP or TLS, with disk-backed delivery and failover per destination, or OTLP log records over HTTP to an OpenTelemetry Collector or any OTLP endpoint. Example: the same events go to a SIEM as RFC 5424 syslog over TLS on 6514 and to an NDJSON archive on 2514, each with its own queue.

Destinations

Five destination types, from syslog to OpenTelemetry

DPLens works with any SIEM that accepts syslog or JSON, speaks the Splunk protocols directly, and sends OTLP over HTTP to an OpenTelemetry Collector or any OTLP endpoint. On syslog, Snare, NDJSON and Splunk destinations, TLS is recommended, with certificate validation on by default and mutual TLS where the receiver requires it.

Destination types in DPLens 1.0
ReceiverFormatsConventional port
Syslog SIEMRFC 5424 or RFC 3164, over TLS, TCP or UDP6514 (TLS), 514
Snare collectorSnare tab-separated fields, or Snare inside an RFC 3164 syslog line514
NDJSON collectorOne JSON object per line, keeping parsed fields intact. Raw relay is also available.2514
SplunkCooked S2S, as the Universal Forwarder sends it, with TLS when your indexer uses it; or the HTTP Event Collector (HEC) over HTTPS. Optional indexer acknowledgement.9997, 8088
OpenTelemetryOTLP over HTTP with protobuf encoding, to an OpenTelemetry Collector or any OTLP endpoint. Events arrive as OTLP log records. More on OpenTelemetry4318

Fan-out

One pipeline can deliver the same processed events to several destinations at once, such as a hot SIEM and a low-cost archive.

Failover

An ordered list of addresses, with automatic failback once the primary is healthy again. Splunk destinations can instead use a pool of equal indexers.

Disk-backed delivery

Each destination queues to its own on-disk cache, sized for the outage you want to ride out. When it fills, you choose: pause collection, drop oldest or drop newest, and every drop is counted on Overview. Splunk destinations can also use indexer acknowledgement.

DPLens Manager

Run the whole fleet from one place

DPLens Manager is included in every DPLens subscription. It gives you central configuration, fleet health monitoring, and deployment and upgrades for your DPLens agents, and it runs on your own infrastructure.

Central configuration

Manage the configuration of your DPLens agents centrally, rather than machine by machine.

Fleet health monitoring

Watch the health of every DPLens agent across your estate.

Deployment and upgrades

Deploy DPLens agents and keep them up to date across the fleet.

Self-hosted and air-gap capable

DPLens Manager runs on your infrastructure, including in air-gapped networks, with no vendor cloud involved.

Operations

A console on every host, and health you can alert on

Alongside DPLens Manager, each agent serves its own web console for hands-on inspection. It is reachable from the local machine until you allow other networks.

Overview

Events a second, a per-stage funnel of what each rule removed, estimated GB a day out, losses by cause and what the reduction is worth at your cost per gigabyte.

Recommendations

A local scan of the machine's roles, services, disks and audit policy suggests what is worth collecting. Nothing is sent anywhere.

Live stream

Events as they leave, encoded exactly as the destination receives them, in masked form. A test event proves the path end to end.

Staged changes

Edits are validated and applied as one set, and a set that comes back unhealthy offers one-click roll back.

Health and audit

Components report Healthy, Degraded, Restarting or Quarantined, and a failing source is isolated so the rest keeps running. A tamper-evident audit trail records every change.

Backup and upgrades

Back up the configuration and licence, and working state rebuilds itself. In-place upgrades keep configuration, licence, credentials, collection positions, queued events and the audit trail.

Requirements

Supported Windows versions and what to provision

Windows Server 2025, 2022, 2019 and 2016, and Windows 11 and 10, on x64. Server Core is supported.

Provisioning allowances per host
ResourceAllow
Disk, program files30 MB
Disk, working state1 GB, plus your disk-cache sizing per destination
Memory150 MB
CPULow at idle; a busy pipeline scales with your event rate
Ports (DPLens listens only on what you enable)
DirectionPurposePort
InboundWeb console over HTTPS (local machine only by default)8443/TCP
InboundSyslog receiver, when enabled514 UDP or TCP
InboundNetFlow and IPFIX receiver, when enabled2055 UDP or TCP
OutboundYour destinations: syslog and Snare, syslog over TLS, NDJSON, Splunk S2S, Splunk HEC, OpenTelemetry (all configurable)514, 6514, 2514, 9997, 8088, 4318

Performance

How fast is DPLens?

In our lab benchmark, DPLens delivered more than 30× the throughput of the established Windows agents we tested, at about a tenth of the CPU per event, with no events lost.

30×+the throughput of the established Windows agents we tested
~1/10of their CPU per event
~26,000events delivered per second on one 8-core server
0events lost
Lab benchmark results, medians (23 September 2026)
MeasureDPLens 1.0Established Windows agents tested
Events delivered per second25,956–27,515601–855
Box CPU per event103–112 µs1,127–1,834 µs
Events lostNoneNone
How we measured
  • DPLens 1.0 release build against established Windows log agents, which we do not name.
  • One 8-core Xeon E5-2430 v2 machine, the same for every agent.
  • The same Windows Event Log channel of 11,364,792 records, read into the same loopback receiver.
  • Each agent in its native wire format; DPLens in Snare, Splunk S2S and NDJSON.
  • Three 60-second repetitions per agent, reported as medians. Run on 23 September 2026.

Lab figures, not a guarantee: real throughput depends on your hardware, sources and pipeline rules. Request an evaluation licence to measure DPLens on your own servers, or contact us to discuss the benchmark.

Where it fits

Edge processing for your Windows estate

DPLens does edge log processing on each Windows host, so reduction happens before data is billed and there is no separate processing tier to build or run. It is made for the Windows estate: replacing the Splunk Universal Forwarder or Snare and cutting ingest at the source, with DPLens Manager for central control and nothing calling home.

Next: the solutions it is built for, SIEM integrations, comparisons with other agents and pipelines, the savings calculator, the Trust Centre and the licensing model.

Secure by design

An agent you can defend in a security review.

Signed and verifiableEvery release is signed and ships with checksums and a software bill of materials, so you can verify it before it reaches a server.
Nothing calls homeNo telemetry, no licence server and no automatic updates. Your data goes only where you send it.
Secure engineeringBuilt and tested to modern secure-development practice, for software that runs on your most sensitive servers.
Least privilegeRuns with only the access it needs, with administration kept apart from collection.

FAQ

Questions buyers ask

Does DPLens work with the SIEM we already run?

Yes. DPLens collects, reduces and delivers log data to the SIEM you already run: Splunk natively, over cooked S2S or HEC, and any SIEM that accepts syslog or JSON, including IBM QRadar, Securonix, Devo and Secureworks Taegis. It also sends to any pipeline built on an OpenTelemetry Collector.

Which systems does DPLens run on?

Windows Server 2025, 2022, 2019 and 2016, and Windows 11 and 10, on x64, including Server Core. Its syslog receiver also brings in events from Linux hosts and network devices.

Which destinations can DPLens send to?

Five types: syslog (RFC 5424 or RFC 3164), Snare, NDJSON (plus raw relay), Splunk (cooked S2S or HEC) and OpenTelemetry (OTLP over HTTP with protobuf encoding, conventionally port 4318). That covers any SIEM that accepts syslog or JSON, and any pipeline built on an OpenTelemetry Collector.

How fast is DPLens?

In our lab benchmark, more than 30× the throughput of the established Windows agents we tested, at about a tenth of the CPU per event, with no events lost. See how we measured.

Is there central management?

Yes. DPLens Manager, included in every subscription, provides central configuration, fleet health monitoring, and deployment and upgrades for your DPLens agents. It is self-hosted and air-gap capable. Each agent also has its own console for local inspection.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.