How it works
A security data pipeline that runs on the Windows host itself.
DPLens collects, reduces, masks and delivers log data on the machine that produced it, and DPLens Manager runs the whole fleet from one place. No vendor cloud sits between your logs and your SIEM.
- Windows x64
- Edge log processing
- Syslog, Snare, NDJSON, Splunk, OpenTelemetry
- DPLens Manager included
In short
DPLens is a security data pipeline that runs on each Windows host: it collects event logs, log files, file-integrity scans, syslog and NetFlow, reduces and masks them in seven stages, and delivers the result to your SIEM over syslog, Snare, NDJSON or the Splunk protocols, or to an OpenTelemetry Collector over OTLP. Processing happens on the host, so there is no separate processing tier to build, and DPLens Manager, included in every subscription, gives you central configuration, fleet health monitoring, and deployment and upgrades. In our lab benchmark DPLens delivered more than 30× the throughput of the established Windows agents we tested, at about a tenth of the CPU per event.
Architecture
One agent per Windows host, managed centrally
DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. Each machine runs one signed agent as a Windows service. Reduction happens before data leaves the host, so the SIEM only receives what you chose to send.
| Sources (in) | Stages (on the host) | Destinations (out) |
|---|---|---|
| Windows Event Log channels | 1. Filter | Syslog (RFC 5424 or 3164) |
| Log files (path or wildcard) | 2. Parse and normalise | Snare |
| File integrity (scheduled scans) | 3. Aggregate, then 4. Optimise | NDJSON collector |
| Syslog receiver (UDP or TCP) | 5. Enrich | Splunk cooked S2S or HTTP Event Collector (HEC) |
| NetFlow v5 and IPFIX receiver | 6. Mask, then 7. Rate limit | OpenTelemetry (OTLP over HTTP) |
01
Self-contained
One signed installer is all a host needs. There is nothing else to install or patch alongside it, and no internet access is required.
02
Configuration as code
Define a configuration once, review it, keep it in source control and apply it across your fleet. Credentials are kept out of it.
03
Rolled out your way
Deploy and upgrade with DPLens Manager, or with the tools you already use: Group Policy, Intune, Configuration Manager or an RMM, plus golden images and VDI. See deployment.
Sources
What it collects
Collection resumes exactly where it stopped after a restart, upgrade or pause, so nothing is read twice or skipped.
| Source | What it does |
|---|---|
| Windows Event Log | Any number of channels, including Security, Sysmon and your own custom channels. Select events by severity, Event ID, provider or XPath, and backfill history when you need it. |
| Log files | Any path or wildcard, on local disks or network shares. Rotated files are followed, new matching files are picked up, and UTF-8 and UTF-16 are detected. |
| File integrity | Watches files, folders and wildcards against a baseline, scanning every 15 minutes, hourly or daily. Changes arrive as events. |
| Syslog receiver | Receives RFC 3164 and RFC 5424 syslog over UDP or TCP from firewalls, switches and appliances, from the networks you allow. |
| NetFlow and IPFIX receiver | Receives NetFlow v5 and IPFIX over UDP, and IPFIX over TCP, so flow records go through the same pipeline as your logs. |
Pipeline
What happens between collection and delivery?
Seven processing stages, always in this order: filter, parse, aggregate, optimise, enrich, mask, rate limit. Run several pipelines, each delivering to several destinations at once. Every drop, mask, aggregation and failover is counted and attributed to the rule that caused it.
Collect
Read from the five sources above and select events at the source, the cheapest reduction there is. Example: one source reads Security, System, Application and Sysmon, keeping only the Event IDs you name.
Filter
Keep or drop events with rules that test values, text, patterns, numbers, lists and network ranges, combined however you need. Example: keep Event IDs 4624, 4625, 4634, 4688 and 4720, and drop those whose target user name ends in
$(machine accounts).Parse
Turn raw text into fields from JSON, syslog, delimited, key-value or free-text formats, and normalise Windows security events to CIM or OCSF names. Events that fail to parse are routed and counted, so a format change surfaces straight away.
Aggregate
Collapse repeats into one representative event carrying the count, grouped by the fields you choose over a time window. Example: failed logons (Event ID 4625) for the same user and address inside 60 seconds become one event.
Optimise
Remove fields that hold a placeholder rather than a fact, such as an empty value, a dash, "N/A" or a null SID, so every event is smaller without losing information. You choose which values to remove, and the console shows the estimated saving.
Enrich
Add static tags and host facts such as host name, domain, OS version, local addresses and time zone, plus the machine's public IP if you choose. Example: tag every event with
site: lon-dc1andenv: prod.Mask
Detect card numbers, email and IP addresses, US SSNs, UK National Insurance numbers, phone numbers or your own pattern, then redact, partially mask, tokenise or hash. Masking happens before anything is stored or sent; every masking decision is counted, and masking-policy changes are recorded in the tamper-evident audit trail. Example: keep only the last four digits of a card number.
Rate limit
Cap events or bytes per second, with short bursts smoothed out, so one noisy machine cannot exhaust a licence or swamp an indexer. Example: 2,000 events a second with bursts to 4,000. Every shed event is counted.
Deliver
Encode for the receiver and send it: syslog, Snare, NDJSON and Splunk over UDP, TCP or TLS, with disk-backed delivery and failover per destination, or OTLP log records over HTTP to an OpenTelemetry Collector or any OTLP endpoint. Example: the same events go to a SIEM as RFC 5424 syslog over TLS on 6514 and to an NDJSON archive on 2514, each with its own queue.
Destinations
Five destination types, from syslog to OpenTelemetry
DPLens works with any SIEM that accepts syslog or JSON, speaks the Splunk protocols directly, and sends OTLP over HTTP to an OpenTelemetry Collector or any OTLP endpoint. On syslog, Snare, NDJSON and Splunk destinations, TLS is recommended, with certificate validation on by default and mutual TLS where the receiver requires it.
| Receiver | Formats | Conventional port |
|---|---|---|
| Syslog SIEM | RFC 5424 or RFC 3164, over TLS, TCP or UDP | 6514 (TLS), 514 |
| Snare collector | Snare tab-separated fields, or Snare inside an RFC 3164 syslog line | 514 |
| NDJSON collector | One JSON object per line, keeping parsed fields intact. Raw relay is also available. | 2514 |
| Splunk | Cooked S2S, as the Universal Forwarder sends it, with TLS when your indexer uses it; or the HTTP Event Collector (HEC) over HTTPS. Optional indexer acknowledgement. | 9997, 8088 |
| OpenTelemetry | OTLP over HTTP with protobuf encoding, to an OpenTelemetry Collector or any OTLP endpoint. Events arrive as OTLP log records. More on OpenTelemetry | 4318 |
Fan-out
One pipeline can deliver the same processed events to several destinations at once, such as a hot SIEM and a low-cost archive.
Failover
An ordered list of addresses, with automatic failback once the primary is healthy again. Splunk destinations can instead use a pool of equal indexers.
Disk-backed delivery
Each destination queues to its own on-disk cache, sized for the outage you want to ride out. When it fills, you choose: pause collection, drop oldest or drop newest, and every drop is counted on Overview. Splunk destinations can also use indexer acknowledgement.
DPLens Manager
Run the whole fleet from one place
DPLens Manager is included in every DPLens subscription. It gives you central configuration, fleet health monitoring, and deployment and upgrades for your DPLens agents, and it runs on your own infrastructure.
Central configuration
Manage the configuration of your DPLens agents centrally, rather than machine by machine.
Fleet health monitoring
Watch the health of every DPLens agent across your estate.
Deployment and upgrades
Deploy DPLens agents and keep them up to date across the fleet.
Self-hosted and air-gap capable
DPLens Manager runs on your infrastructure, including in air-gapped networks, with no vendor cloud involved.
Operations
A console on every host, and health you can alert on
Alongside DPLens Manager, each agent serves its own web console for hands-on inspection. It is reachable from the local machine until you allow other networks.
Overview
Events a second, a per-stage funnel of what each rule removed, estimated GB a day out, losses by cause and what the reduction is worth at your cost per gigabyte.
Recommendations
A local scan of the machine's roles, services, disks and audit policy suggests what is worth collecting. Nothing is sent anywhere.
Live stream
Events as they leave, encoded exactly as the destination receives them, in masked form. A test event proves the path end to end.
Staged changes
Edits are validated and applied as one set, and a set that comes back unhealthy offers one-click roll back.
Health and audit
Components report Healthy, Degraded, Restarting or Quarantined, and a failing source is isolated so the rest keeps running. A tamper-evident audit trail records every change.
Backup and upgrades
Back up the configuration and licence, and working state rebuilds itself. In-place upgrades keep configuration, licence, credentials, collection positions, queued events and the audit trail.
Requirements
Supported Windows versions and what to provision
Windows Server 2025, 2022, 2019 and 2016, and Windows 11 and 10, on x64. Server Core is supported.
| Resource | Allow |
|---|---|
| Disk, program files | 30 MB |
| Disk, working state | 1 GB, plus your disk-cache sizing per destination |
| Memory | 150 MB |
| CPU | Low at idle; a busy pipeline scales with your event rate |
| Direction | Purpose | Port |
|---|---|---|
| Inbound | Web console over HTTPS (local machine only by default) | 8443/TCP |
| Inbound | Syslog receiver, when enabled | 514 UDP or TCP |
| Inbound | NetFlow and IPFIX receiver, when enabled | 2055 UDP or TCP |
| Outbound | Your destinations: syslog and Snare, syslog over TLS, NDJSON, Splunk S2S, Splunk HEC, OpenTelemetry (all configurable) | 514, 6514, 2514, 9997, 8088, 4318 |
Performance
How fast is DPLens?
In our lab benchmark, DPLens delivered more than 30× the throughput of the established Windows agents we tested, at about a tenth of the CPU per event, with no events lost.
| Measure | DPLens 1.0 | Established Windows agents tested |
|---|---|---|
| Events delivered per second | 25,956–27,515 | 601–855 |
| Box CPU per event | 103–112 µs | 1,127–1,834 µs |
| Events lost | None | None |
- DPLens 1.0 release build against established Windows log agents, which we do not name.
- One 8-core Xeon E5-2430 v2 machine, the same for every agent.
- The same Windows Event Log channel of 11,364,792 records, read into the same loopback receiver.
- Each agent in its native wire format; DPLens in Snare, Splunk S2S and NDJSON.
- Three 60-second repetitions per agent, reported as medians. Run on 23 September 2026.
Where it fits
Edge processing for your Windows estate
DPLens does edge log processing on each Windows host, so reduction happens before data is billed and there is no separate processing tier to build or run. It is made for the Windows estate: replacing the Splunk Universal Forwarder or Snare and cutting ingest at the source, with DPLens Manager for central control and nothing calling home.
Next: the solutions it is built for, SIEM integrations, comparisons with other agents and pipelines, the savings calculator, the Trust Centre and the licensing model.
Secure by design
An agent you can defend in a security review.
FAQ
Questions buyers ask
Does DPLens work with the SIEM we already run?
Yes. DPLens collects, reduces and delivers log data to the SIEM you already run: Splunk natively, over cooked S2S or HEC, and any SIEM that accepts syslog or JSON, including IBM QRadar, Securonix, Devo and Secureworks Taegis. It also sends to any pipeline built on an OpenTelemetry Collector.
Which systems does DPLens run on?
Windows Server 2025, 2022, 2019 and 2016, and Windows 11 and 10, on x64, including Server Core. Its syslog receiver also brings in events from Linux hosts and network devices.
Which destinations can DPLens send to?
Five types: syslog (RFC 5424 or RFC 3164), Snare, NDJSON (plus raw relay), Splunk (cooked S2S or HEC) and OpenTelemetry (OTLP over HTTP with protobuf encoding, conventionally port 4318). That covers any SIEM that accepts syslog or JSON, and any pipeline built on an OpenTelemetry Collector.
How fast is DPLens?
In our lab benchmark, more than 30× the throughput of the established Windows agents we tested, at about a tenth of the CPU per event, with no events lost. See how we measured.
Is there central management?
Yes. DPLens Manager, included in every subscription, provides central configuration, fleet health monitoring, and deployment and upgrades for your DPLens agents. It is self-hosted and air-gap capable. Each agent also has its own console for local inspection.
See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.