Solutions
Windows log collection solutions: what teams use DPLens for.
Most teams start by replacing an agent they already run, the Splunk Universal Forwarder or Snare, and cutting what reaches the SIEM. The same agent then covers file integrity monitoring, masking of personal data and offline, air-gapped collection.
- Windows Server 2016–2025
- Windows 10 and 11
- x64
- Self-hosted
- No vendor control plane
In short
DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. Teams use it to replace the Splunk Universal Forwarder or a Snare agent, cut SIEM ingest by filtering and masking on the host, add file integrity monitoring, and collect logs in air-gapped networks. It delivers to Splunk natively, to any SIEM that accepts syslog, Snare or JSON, or to an OpenTelemetry Collector over OTLP/HTTP.
Seven jobs, one agent
Solutions
Each page explains what DPLens does for that job, the outcome you can expect, and where to find the detail in the documentation.
01
Splunk Universal Forwarder replacement
Deliver to your indexers over cooked S2S or HEC with the index and sourcetype your searches expect, and filter noisy events on the host before they count against your ingest licence.
Read more →02
Snare agent replacement
Snare-format output that a collector already configured for Snare records can receive, with TCP or TLS delivery from a disk-backed queue and edge filtering to cut volume.
Read more →03
Windows Event Log collection
Collect Security, System, Sysmon and custom channels with one source, and filter at the source by Event ID, channel, provider or query so only the events you need are collected.
Read more →04
SIEM cost reduction
Filter, aggregate and rate-limit on the host, so the reduction lands on your SIEM licence rather than further downstream. Every drop is counted and attributed to the rule that caused it.
Read more →05
Windows file integrity monitoring
Scheduled change detection for files, folders and wildcards, every 15 minutes, hourly or daily, from the agent you already run. Supports PCI DSS v4.0.1 Requirement 11.5.2.
Read more →06
Log masking and PII redaction
Redact, partially mask, tokenise or hash card numbers, email addresses, UK National Insurance numbers and your own patterns before anything is cached or sent.
Read more →07
Air-gapped log collection
Offline signed licence keys, no telemetry, no licensing service, and updates on your schedule. An air-gapped machine is a normal deployment, not a special mode.
Read more →Whichever you start with
What every solution shares
Every solution is the same agent and the same pipeline, configured differently. Events pass through seven stages in a fixed order (filter, parse, aggregate, optimise, enrich, mask, rate limit) and can be delivered to several destinations at once.
- One signed executable and its installer. No .NET, Java or database to install first.
- Disk-backed delivery to every destination, so an outage queues events instead of discarding them.
- Nothing dropped silently: every drop, mask and aggregation is counted and attributed to its rule.
- Licensed per agent and per network source with an offline key, with no per-GB ingestion cost.
- DPLens Manager for central configuration, fleet health monitoring, deployment and upgrades: self-hosted, air-gap capable and included in every subscription. Agents can also be deployed with Group Policy, Intune or Configuration Manager.
- Five destination types: syslog, Snare, NDJSON, Splunk (S2S and HEC) and OpenTelemetry over OTLP/HTTP.
Both figures are in our lab benchmark: lab figures, not a guarantee, since real throughput depends on hardware, sources and pipeline rules.
Not sure where to start?
Three ways in
See how the platform works
Sources, the seven pipeline stages and every destination, on one page.
Read more →Compare it with what you run
Dated, factual comparisons with the Universal Forwarder, Edge Processor, Snare, NXLog, Cribl Edge and Elastic Agent.
Read more →Talk it through
Book a demo, or request an evaluation licence and try it on a test host.
Read more →Secure by design
An agent you can defend in a security review.
See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.