Snare agent replacement

Replace the Snare agent and keep your collector's Snare parser.

DPLens emits Snare-format records from a Windows agent over TCP or TLS, from a disk-backed queue. The collector that parses Snare today keeps receiving the format it expects, and a receiver outage queues events instead of losing them.

  • Snare, bare or in RFC 3164 syslog
  • TCP, TLS or UDP
  • Disk-backed delivery
  • Edge filtering
  • Native Splunk delivery too

In short

DPLens replaces the Snare agent on Windows hosts without changing the receiving side: it emits Snare's tab-separated format, bare or inside an RFC 3164 syslog line, so a collector already configured for Snare records can receive from it. What changes is delivery (TCP or TLS from a per-destination disk cache, with failover and every drop counted) and volume, because events are filtered on the host first. The same pipeline can also deliver natively to Splunk.

26,000–27,500events a second on one 8-core Xeon E5-2430 v2, in our lab benchmark
About 0.1 msof CPU per event, with messages rendered

In our lab benchmark, DPLens held that rate in Snare, S2S and NDJSON formats. Lab figures, not a guarantee: measure your current agent on the same server during a pilot.

Snare output

Will my Snare collector accept DPLens records?

DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. It produces the long-established Snare format in two shapes; pick the one your collector is configured for.

Snare output formats
FormatWhat it producesUse it when
SnareSnare's tab-separated fieldsYour collector takes bare Snare records.
Snare in RFC 3164 syslogThe same fields inside an RFC 3164 syslog lineYour collector expects a syslog wrapper. This is what the console's Snare receiver preset selects (TCP, port 514).

Records shaped to your collector. Set the severity, host name, Snare criticality and syslog facility each record carries, so they match what your collector's rules expect.

The category column. DPLens can fill Snare's category column from each event's task name. Switch on the Snare option for the source if your collector uses it.

To see precisely what the collector will receive, use Send test event from a source's row menu and watch Live stream with the Snare destination selected: it shows the exact record, tabs and all.

Reliable delivery

What happens when the collector is down?

DPLens delivers Snare records over TLS or TCP from a disk-backed queue, with failover and every drop counted. UDP is available too, for receivers that require it.

Choosing a transport for a Snare destination
TransportWhat you get
TLS (recommended)Disk-backed queue, failover, reconnection, counted losses, and encryption with certificate validation on by default
TCPDisk-backed queue, failover, reconnection and counted losses
UDPCompatibility with receivers that accept only UDP

01

A disk-backed queue per destination

If the collector is unreachable, events queue on disk and are delivered when it returns. You choose the size, and the console tells you how many hours of your measured traffic it holds.

02

Failover and failback

Give an ordered list of collectors. DPLens moves to the next when the current one stops accepting, and moves back once the first has recovered and stayed healthy.

03

Nothing dropped silently

If a cache fills, you choose: pause collection while Windows holds the events, drop the oldest, or drop the newest. Whichever you choose, the count appears on the Overview.

Edge filtering

Send your collector less, on purpose

Filtering happens on the Windows host, before records are formatted and sent.

Filter at the source

Choose channels, a severity, Event IDs to include or exclude, and providers. DPLens filters at the source, so only the events you need are collected. One source can collect Security, System, Sysmon and custom channels together.

Shape in the pipeline

Keep or drop on field conditions, collapse repeated failures into one event with a count, mask personal data before it is cached or sent, and cap what one noisy machine can send. Every drop is counted and attributed to its rule.

More on Windows Event Log collection and reducing SIEM ingest at the source.

Snare to Splunk

Can I feed a Snare collector and Splunk at the same time?

Yes. DPLens speaks the Splunk forwarder protocol (cooked S2S) and the HTTP Event Collector natively, so Splunk receives Windows events directly, with the index and sourcetype you choose.

One pipeline delivers to several destinations at once, each with its own disk-backed queue, so an outage at one leaves the other flowing. Keep the Snare collector fed while you build and check your Splunk content, then retire the Snare destination when you are ready. Both receive the same filtered, processed events. The Splunk integration page covers index, sourcetype and indexer pools, and Splunk Universal Forwarder replacement covers the Splunk side of a migration.

How to switch

How do I replace a Snare agent without a gap?

This follows the documented procedure in Replacing an existing Snare agent: run alongside, compare, then remove.

  1. Note what the current agent sends

    Record the channels and filters, the collector's address and port, the transport, and whether the collector uses the category column or expects a syslog wrapper.

  2. Configure DPLens alongside

    Point it at the same collector in the Snare format your collector expects, with the category column filled if your collector uses it. Prove the path with a test event.

  3. Compare what arrives

    Compare records from each agent for a period you are comfortable with. Keep it short: while both run, your collector receives every event twice.

  4. Stop, remove and roll out

    Once the records match, retire the old agent and roll DPLens out to the rest of the estate with your validated configuration. DPLens Manager handles central configuration, deployment, upgrades and fleet health, self-hosted and included in every subscription; you can also deploy with Group Policy, Intune or Configuration Manager.

Secure by design

An agent you can defend in a security review.

Signed and verifiableEvery release is signed and ships with checksums and a software bill of materials, so you can verify it before it reaches a server.
Nothing calls homeNo telemetry, no licence server and no automatic updates. Your data goes only where you send it.
Secure engineeringBuilt and tested to modern secure-development practice, for software that runs on your most sensitive servers.
Least privilegeRuns with only the access it needs, with administration kept apart from collection.

FAQ

Questions Snare users ask

Will my collector's Snare parser accept DPLens records?

A collector already configured to receive Snare records can receive from DPLens. Confirm it on your own collector by running DPLens alongside the existing agent and comparing what arrives; Live stream shows the exact record DPLens sends.

Should I send bare Snare records or wrap them in syslog?

Use whichever your collector is set up for. DPLens sends bare tab-separated Snare records, or the same fields inside an RFC 3164 syslog line, which is what the console's Snare receiver preset selects.

Can DPLens fill Snare's category column?

Yes. Switch on the Snare option for the source and DPLens fills the column from each event's task name.

Can I keep sending over UDP?

Yes, where the receiver requires it. TCP or TLS add the disk-backed queue, failover and counted delivery, so use them wherever your collector allows.

How do we roll DPLens out across the estate?

With DPLens Manager, which provides central configuration, fleet health monitoring, deployment and upgrades. It is self-hosted, air-gap capable and included in every subscription. Agents can also be deployed with Group Policy, Intune or Configuration Manager.

How is it licensed?

With an offline, signed key bound to one machine or to Active Directory domains. The agent entitlement covers every local source, every stage and every destination, with no per-GB cost. See the licensing model.

Snare is a trademark of its owner, and Splunk is a trademark of Splunk LLC. DPLens is not affiliated with or endorsed by either. The names are used only to say what DPLens interoperates with.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.