Solutions

Windows log collection solutions: what teams use DPLens for.

Most teams start by replacing an agent they already run, the Splunk Universal Forwarder or Snare, and cutting what reaches the SIEM. The same agent then covers file integrity monitoring, masking of personal data and offline, air-gapped collection.

  • Windows Server 2016–2025
  • Windows 10 and 11
  • x64
  • Self-hosted
  • No vendor control plane

In short

DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. Teams use it to replace the Splunk Universal Forwarder or a Snare agent, cut SIEM ingest by filtering and masking on the host, add file integrity monitoring, and collect logs in air-gapped networks. It delivers to Splunk natively, to any SIEM that accepts syslog, Snare or JSON, or to an OpenTelemetry Collector over OTLP/HTTP.

Seven jobs, one agent

Solutions

Each page explains what DPLens does for that job, the outcome you can expect, and where to find the detail in the documentation.

01

Splunk Universal Forwarder replacement

Deliver to your indexers over cooked S2S or HEC with the index and sourcetype your searches expect, and filter noisy events on the host before they count against your ingest licence.

Read more →

02

Snare agent replacement

Snare-format output that a collector already configured for Snare records can receive, with TCP or TLS delivery from a disk-backed queue and edge filtering to cut volume.

Read more →

03

Windows Event Log collection

Collect Security, System, Sysmon and custom channels with one source, and filter at the source by Event ID, channel, provider or query so only the events you need are collected.

Read more →

04

SIEM cost reduction

Filter, aggregate and rate-limit on the host, so the reduction lands on your SIEM licence rather than further downstream. Every drop is counted and attributed to the rule that caused it.

Read more →

05

Windows file integrity monitoring

Scheduled change detection for files, folders and wildcards, every 15 minutes, hourly or daily, from the agent you already run. Supports PCI DSS v4.0.1 Requirement 11.5.2.

Read more →

06

Log masking and PII redaction

Redact, partially mask, tokenise or hash card numbers, email addresses, UK National Insurance numbers and your own patterns before anything is cached or sent.

Read more →

07

Air-gapped log collection

Offline signed licence keys, no telemetry, no licensing service, and updates on your schedule. An air-gapped machine is a normal deployment, not a special mode.

Read more →

Whichever you start with

What every solution shares

Every solution is the same agent and the same pipeline, configured differently. Events pass through seven stages in a fixed order (filter, parse, aggregate, optimise, enrich, mask, rate limit) and can be delivered to several destinations at once.

  • One signed executable and its installer. No .NET, Java or database to install first.
  • Disk-backed delivery to every destination, so an outage queues events instead of discarding them.
  • Nothing dropped silently: every drop, mask and aggregation is counted and attributed to its rule.
  • Licensed per agent and per network source with an offline key, with no per-GB ingestion cost.
  • DPLens Manager for central configuration, fleet health monitoring, deployment and upgrades: self-hosted, air-gap capable and included in every subscription. Agents can also be deployed with Group Policy, Intune or Configuration Manager.
  • Five destination types: syslog, Snare, NDJSON, Splunk (S2S and HEC) and OpenTelemetry over OTLP/HTTP.
More than 30×the throughput of the established Windows agents we tested
About a tenthof their CPU per event

Both figures are in our lab benchmark: lab figures, not a guarantee, since real throughput depends on hardware, sources and pipeline rules.

Secure by design

An agent you can defend in a security review.

Signed and verifiableEvery release is signed and ships with checksums and a software bill of materials, so you can verify it before it reaches a server.
Nothing calls homeNo telemetry, no licence server and no automatic updates. Your data goes only where you send it.
Secure engineeringBuilt and tested to modern secure-development practice, for software that runs on your most sensitive servers.
Least privilegeRuns with only the access it needs, with administration kept apart from collection.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.