Splunk Universal Forwarder replacement

Replace the Splunk Universal Forwarder and cut ingest before it leaves the host.

Deliver to your existing indexers over cooked S2S on 9997, or to the HTTP Event Collector on 8088, with the index and sourcetype your searches already expect, and drop the noise on the Windows host first.

  • Cooked S2S on 9997
  • HEC on 8088
  • Equal-peer indexer pool
  • Optional indexer acknowledgement
  • Windows x64

In short

DPLens replaces the Splunk Universal Forwarder (UF) on Windows hosts: it sends to the same indexers over cooked S2S, or to HEC, with the same index and sourcetype. Unlike the UF, it filters, aggregates and masks events on the host before they are sent, so the reduction lands on your ingest licence. The same pipeline can also deliver to a syslog, Snare or JSON receiver, or to an OpenTelemetry Collector.

26,000–27,500events a second on one 8-core Xeon E5-2430 v2, in our lab benchmark
About 0.1 msof CPU per event, with messages rendered

In our lab benchmark, DPLens held that rate in Snare, S2S and NDJSON formats. Lab figures, not a guarantee: measure your current agent on the same server during a pilot.

What DPLens speaks

Can DPLens send to my existing Splunk indexers?

Yes. DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows, with two Splunk destination types: S2S for indexers, a load-balanced pool and indexer acknowledgement; HEC where your platform exposes a collector endpoint and authenticates with a token.

01

Cooked S2S to an indexer pool

DPLens speaks the protocol Splunk forwarders use to reach an indexer or heavy forwarder. Traffic is balanced across every indexer in the pool; a member that stops accepting is rested until it recovers, and events queue on disk only if every indexer is unavailable.

02

Optional indexer acknowledgement

Switch it on and an event counts as delivered only once the indexer confirms it, with automatic re-sending if confirmation is late.

03

HEC on 8088

Send batched events to the HEC event endpoint, or records as-is to the raw endpoint. TLS is on by default, and the token is stored securely and never shown in the configuration, the logs or the console.

S2S supports TLS and mutual TLS: switch it on where your indexers expect it, just as you would on the UF. The Splunk integration page covers every setting.

From the UF to DPLens

How does UF configuration map to DPLens?

The settings a Windows UF relies on in inputs.conf and outputs.conf carry straight across.

UF settings and their DPLens equivalents
UF settingDPLens equivalentNotes
[WinEventLog://Security] stanzasA Windows Event Log sourceOne source reads any number of channels, including Sysmon and custom ones.
whitelist / blacklist on event codesSource filters: Event IDs to include or exclude, providers, severity, or your own queryOnly the events you want are collected.
renderXmlClassic or XML event format on the Splunk destinationClassic is the familiar flattened form; XML is the raw event XML. Match what your searches were written against.
current_only / start_fromNew events only, or a one-off backfillChosen per source.
[monitor://…] file inputsA log file source with a path or wildcardRotated files are followed; UTF-8 and UTF-16 are detected.
index, sourcetype, source, hostSet on the Splunk destinationEach is a fixed value or taken from an event field, with per-source overrides.
server in a [tcpout:…] groupAn equal-peer indexer pool or an ordered failover listMembers that stop accepting are rested and rejoin once healthy.
autoLBFrequency / autoLBVolumeLoad-balancing rotation by time or by volumeA recovered indexer rejoins once it has stayed healthy.
useACKIndexer acknowledgementWindow, timeout and resend limit are configurable.
Output TLS settingsTLS and mutual TLSUse your own CA or the Windows trust store.
Deployment serverDPLens ManagerCentral configuration, deployment, upgrades and fleet health monitoring. Self-hosted, air-gap capable and included in every subscription.

Filter before ingest

How does DPLens reduce Splunk ingest?

It filters in two places, both on the Windows host, before anything crosses the network.

At the source

Filter at the source by severity, Event IDs to include or exclude, provider or query, so only the events you want are collected. Use this when a whole Event ID is of no interest.

In the pipeline

A filter stage keeps or drops events on conditions (equals, contains, pattern, list, address range, numeric comparison), combined however you need. Aggregation collapses repeats into one event with a count, and rate control caps what one noisy machine can send.

Common candidates on a busy estate are Event ID 4662, 4663 and the Windows Filtering Platform events 5156 and 5158. Be selective: on domain controllers, Event ID 4662 records directory replication requests that DCSync detection relies on, so filter it by its properties rather than wholesale. The guide to noisy Windows Security Event IDs covers the trade-offs, and SIEM cost reduction covers the other techniques.

Every drop is counted and attributed to the rule that caused it, so you can defend a filter to the detection team. To put a figure on it, try the savings calculator.

How to switch

How do I replace the UF without a gap?

Follow the documented procedure: run alongside, compare, then decommission. The detail is in Replacing an existing forwarder and our UF migration guide.

  1. Inventory what the UF does

    List the channels, files, whitelists and blacklists in inputs.conf, the index and sourcetype each input sets, and the indexers, acknowledgement and TLS in outputs.conf. Note the dashboards you use to watch forwarder health: DPLens Manager provides fleet health monitoring for your DPLens agents.

  2. Configure DPLens alongside

    Deliver to the same indexers with the same index and sourcetype. Build it on one machine in the console and prove the path with a test event.

  3. Compare what arrives

    Search on both over a period you are comfortable with. Both agents send the same events while they run side by side, so your indexers ingest duplicates; keep the pilot group small.

  4. Stop, remove and roll out

    Once the data matches, retire the UF and roll DPLens out to the rest of the estate with your validated configuration. DPLens Manager handles central configuration, deployment, upgrades and fleet health; you can also deploy with Group Policy, Intune or Configuration Manager.

Reduce at the source

Why not use Splunk Edge Processor or Ingest Actions?

Both cut what gets indexed. The difference is where the work happens.

Edge Processor and Ingest Actions work on the Splunk side: on a processing tier between forwarders and indexers, or in the indexing pipeline. By then the data has left the Windows host, and each host still needs a forwarder. DPLens reduces and masks on the host, before anything is cached or sent, and can deliver to Splunk and another receiver at the same time.

  • Reduction and masking happen before data leaves the host.
  • The same agent can send Windows data to Splunk and to any other SIEM or collector you run.
  • You get an agent you can review: signed, with an SBOM and no call-home.

Side by side: DPLens and Splunk Edge Processor compared, and DPLens and the Splunk Universal Forwarder compared.

Secure by design

An agent you can defend in a security review.

Signed and verifiableEvery release is signed and ships with checksums and a software bill of materials, so you can verify it before it reaches a server.
Nothing calls homeNo telemetry, no licence server and no automatic updates. Your data goes only where you send it.
Secure engineeringBuilt and tested to modern secure-development practice, for software that runs on your most sensitive servers.
Least privilegeRuns with only the access it needs, with administration kept apart from collection.

FAQ

Questions Splunk teams ask

Does Splunk see DPLens as a forwarder?

It speaks the forwarder protocol, and its handshake advertises this host's name by default, as a UF does. Events land on the index and sourcetype you configure.

Will my existing searches, dashboards and apps keep working?

Yes, when the index, sourcetype and event format match what they were written against. That is why the procedure runs DPLens alongside the UF and compares what arrives before anything is switched off.

Can I send to Splunk and another SIEM at the same time?

Yes. One pipeline delivers to several destinations at once, such as Splunk and a syslog SIEM or an OpenTelemetry Collector. Each destination has its own queue, so an outage at one leaves the others flowing.

Is there an equivalent of the deployment server?

Yes: DPLens Manager, for central configuration, fleet health monitoring, deployment and upgrades. It is self-hosted, air-gap capable and included in every subscription. Agents can also be deployed with Group Policy, Intune or Configuration Manager.

How is it licensed?

With an offline, signed key bound to one machine or to one or more Active Directory domains. There is no per-GB cost, so filtering more never costs you more. See the licensing model.

Splunk is a trademark of Splunk LLC. DPLens is not affiliated with or endorsed by Splunk. The names are used only to say what DPLens interoperates with.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.