Snare agent replacement
Replace the Snare agent and keep your collector's Snare parser.
DPLens emits Snare-format records from a Windows agent over TCP or TLS, from a disk-backed queue. The collector that parses Snare today keeps receiving the format it expects, and a receiver outage queues events instead of losing them.
- Snare, bare or in RFC 3164 syslog
- TCP, TLS or UDP
- Disk-backed delivery
- Edge filtering
- Native Splunk delivery too
In short
DPLens replaces the Snare agent on Windows hosts without changing the receiving side: it emits Snare's tab-separated format, bare or inside an RFC 3164 syslog line, so a collector already configured for Snare records can receive from it. What changes is delivery (TCP or TLS from a per-destination disk cache, with failover and every drop counted) and volume, because events are filtered on the host first. The same pipeline can also deliver natively to Splunk.
In our lab benchmark, DPLens held that rate in Snare, S2S and NDJSON formats. Lab figures, not a guarantee: measure your current agent on the same server during a pilot.
Snare output
Will my Snare collector accept DPLens records?
DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. It produces the long-established Snare format in two shapes; pick the one your collector is configured for.
| Format | What it produces | Use it when |
|---|---|---|
| Snare | Snare's tab-separated fields | Your collector takes bare Snare records. |
| Snare in RFC 3164 syslog | The same fields inside an RFC 3164 syslog line | Your collector expects a syslog wrapper. This is what the console's Snare receiver preset selects (TCP, port 514). |
Records shaped to your collector. Set the severity, host name, Snare criticality and syslog facility each record carries, so they match what your collector's rules expect.
The category column. DPLens can fill Snare's category column from each event's task name. Switch on the Snare option for the source if your collector uses it.
To see precisely what the collector will receive, use Send test event from a source's row menu and watch Live stream with the Snare destination selected: it shows the exact record, tabs and all.
Reliable delivery
What happens when the collector is down?
DPLens delivers Snare records over TLS or TCP from a disk-backed queue, with failover and every drop counted. UDP is available too, for receivers that require it.
| Transport | What you get |
|---|---|
| TLS (recommended) | Disk-backed queue, failover, reconnection, counted losses, and encryption with certificate validation on by default |
| TCP | Disk-backed queue, failover, reconnection and counted losses |
| UDP | Compatibility with receivers that accept only UDP |
01
A disk-backed queue per destination
If the collector is unreachable, events queue on disk and are delivered when it returns. You choose the size, and the console tells you how many hours of your measured traffic it holds.
02
Failover and failback
Give an ordered list of collectors. DPLens moves to the next when the current one stops accepting, and moves back once the first has recovered and stayed healthy.
03
Nothing dropped silently
If a cache fills, you choose: pause collection while Windows holds the events, drop the oldest, or drop the newest. Whichever you choose, the count appears on the Overview.
Edge filtering
Send your collector less, on purpose
Filtering happens on the Windows host, before records are formatted and sent.
Filter at the source
Choose channels, a severity, Event IDs to include or exclude, and providers. DPLens filters at the source, so only the events you need are collected. One source can collect Security, System, Sysmon and custom channels together.
Shape in the pipeline
Keep or drop on field conditions, collapse repeated failures into one event with a count, mask personal data before it is cached or sent, and cap what one noisy machine can send. Every drop is counted and attributed to its rule.
Snare to Splunk
Can I feed a Snare collector and Splunk at the same time?
Yes. DPLens speaks the Splunk forwarder protocol (cooked S2S) and the HTTP Event Collector natively, so Splunk receives Windows events directly, with the index and sourcetype you choose.
One pipeline delivers to several destinations at once, each with its own disk-backed queue, so an outage at one leaves the other flowing. Keep the Snare collector fed while you build and check your Splunk content, then retire the Snare destination when you are ready. Both receive the same filtered, processed events. The Splunk integration page covers index, sourcetype and indexer pools, and Splunk Universal Forwarder replacement covers the Splunk side of a migration.
How to switch
How do I replace a Snare agent without a gap?
This follows the documented procedure in Replacing an existing Snare agent: run alongside, compare, then remove.
Note what the current agent sends
Record the channels and filters, the collector's address and port, the transport, and whether the collector uses the category column or expects a syslog wrapper.
Configure DPLens alongside
Point it at the same collector in the Snare format your collector expects, with the category column filled if your collector uses it. Prove the path with a test event.
Compare what arrives
Compare records from each agent for a period you are comfortable with. Keep it short: while both run, your collector receives every event twice.
Stop, remove and roll out
Once the records match, retire the old agent and roll DPLens out to the rest of the estate with your validated configuration. DPLens Manager handles central configuration, deployment, upgrades and fleet health, self-hosted and included in every subscription; you can also deploy with Group Policy, Intune or Configuration Manager.
Secure by design
An agent you can defend in a security review.
FAQ
Questions Snare users ask
Will my collector's Snare parser accept DPLens records?
A collector already configured to receive Snare records can receive from DPLens. Confirm it on your own collector by running DPLens alongside the existing agent and comparing what arrives; Live stream shows the exact record DPLens sends.
Should I send bare Snare records or wrap them in syslog?
Use whichever your collector is set up for. DPLens sends bare tab-separated Snare records, or the same fields inside an RFC 3164 syslog line, which is what the console's Snare receiver preset selects.
Can DPLens fill Snare's category column?
Yes. Switch on the Snare option for the source and DPLens fills the column from each event's task name.
Can I keep sending over UDP?
Yes, where the receiver requires it. TCP or TLS add the disk-backed queue, failover and counted delivery, so use them wherever your collector allows.
How do we roll DPLens out across the estate?
With DPLens Manager, which provides central configuration, fleet health monitoring, deployment and upgrades. It is self-hosted, air-gap capable and included in every subscription. Agents can also be deployed with Group Policy, Intune or Configuration Manager.
How is it licensed?
With an offline, signed key bound to one machine or to Active Directory domains. The agent entitlement covers every local source, every stage and every destination, with no per-GB cost. See the licensing model.
See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.