Splunk Universal Forwarder replacement
Replace the Splunk Universal Forwarder and cut ingest before it leaves the host.
Deliver to your existing indexers over cooked S2S on 9997, or to the HTTP Event Collector on 8088, with the index and sourcetype your searches already expect, and drop the noise on the Windows host first.
- Cooked S2S on 9997
- HEC on 8088
- Equal-peer indexer pool
- Optional indexer acknowledgement
- Windows x64
In short
DPLens replaces the Splunk Universal Forwarder (UF) on Windows hosts: it sends to the same indexers over cooked S2S, or to HEC, with the same index and sourcetype. Unlike the UF, it filters, aggregates and masks events on the host before they are sent, so the reduction lands on your ingest licence. The same pipeline can also deliver to a syslog, Snare or JSON receiver, or to an OpenTelemetry Collector.
In our lab benchmark, DPLens held that rate in Snare, S2S and NDJSON formats. Lab figures, not a guarantee: measure your current agent on the same server during a pilot.
What DPLens speaks
Can DPLens send to my existing Splunk indexers?
Yes. DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows, with two Splunk destination types: S2S for indexers, a load-balanced pool and indexer acknowledgement; HEC where your platform exposes a collector endpoint and authenticates with a token.
01
Cooked S2S to an indexer pool
DPLens speaks the protocol Splunk forwarders use to reach an indexer or heavy forwarder. Traffic is balanced across every indexer in the pool; a member that stops accepting is rested until it recovers, and events queue on disk only if every indexer is unavailable.
02
Optional indexer acknowledgement
Switch it on and an event counts as delivered only once the indexer confirms it, with automatic re-sending if confirmation is late.
03
HEC on 8088
Send batched events to the HEC event endpoint, or records as-is to the raw endpoint. TLS is on by default, and the token is stored securely and never shown in the configuration, the logs or the console.
S2S supports TLS and mutual TLS: switch it on where your indexers expect it, just as you would on the UF. The Splunk integration page covers every setting.
From the UF to DPLens
How does UF configuration map to DPLens?
The settings a Windows UF relies on in inputs.conf and outputs.conf carry straight across.
| UF setting | DPLens equivalent | Notes |
|---|---|---|
[WinEventLog://Security] stanzas | A Windows Event Log source | One source reads any number of channels, including Sysmon and custom ones. |
whitelist / blacklist on event codes | Source filters: Event IDs to include or exclude, providers, severity, or your own query | Only the events you want are collected. |
renderXml | Classic or XML event format on the Splunk destination | Classic is the familiar flattened form; XML is the raw event XML. Match what your searches were written against. |
current_only / start_from | New events only, or a one-off backfill | Chosen per source. |
[monitor://…] file inputs | A log file source with a path or wildcard | Rotated files are followed; UTF-8 and UTF-16 are detected. |
index, sourcetype, source, host | Set on the Splunk destination | Each is a fixed value or taken from an event field, with per-source overrides. |
server in a [tcpout:…] group | An equal-peer indexer pool or an ordered failover list | Members that stop accepting are rested and rejoin once healthy. |
autoLBFrequency / autoLBVolume | Load-balancing rotation by time or by volume | A recovered indexer rejoins once it has stayed healthy. |
useACK | Indexer acknowledgement | Window, timeout and resend limit are configurable. |
| Output TLS settings | TLS and mutual TLS | Use your own CA or the Windows trust store. |
| Deployment server | DPLens Manager | Central configuration, deployment, upgrades and fleet health monitoring. Self-hosted, air-gap capable and included in every subscription. |
Filter before ingest
How does DPLens reduce Splunk ingest?
It filters in two places, both on the Windows host, before anything crosses the network.
At the source
Filter at the source by severity, Event IDs to include or exclude, provider or query, so only the events you want are collected. Use this when a whole Event ID is of no interest.
In the pipeline
A filter stage keeps or drops events on conditions (equals, contains, pattern, list, address range, numeric comparison), combined however you need. Aggregation collapses repeats into one event with a count, and rate control caps what one noisy machine can send.
Common candidates on a busy estate are Event ID 4662, 4663 and the Windows Filtering Platform events 5156 and 5158. Be selective: on domain controllers, Event ID 4662 records directory replication requests that DCSync detection relies on, so filter it by its properties rather than wholesale. The guide to noisy Windows Security Event IDs covers the trade-offs, and SIEM cost reduction covers the other techniques.
Every drop is counted and attributed to the rule that caused it, so you can defend a filter to the detection team. To put a figure on it, try the savings calculator.
How to switch
How do I replace the UF without a gap?
Follow the documented procedure: run alongside, compare, then decommission. The detail is in Replacing an existing forwarder and our UF migration guide.
Inventory what the UF does
List the channels, files, whitelists and blacklists in
inputs.conf, the index and sourcetype each input sets, and the indexers, acknowledgement and TLS inoutputs.conf. Note the dashboards you use to watch forwarder health: DPLens Manager provides fleet health monitoring for your DPLens agents.Configure DPLens alongside
Deliver to the same indexers with the same index and sourcetype. Build it on one machine in the console and prove the path with a test event.
Compare what arrives
Search on both over a period you are comfortable with. Both agents send the same events while they run side by side, so your indexers ingest duplicates; keep the pilot group small.
Stop, remove and roll out
Once the data matches, retire the UF and roll DPLens out to the rest of the estate with your validated configuration. DPLens Manager handles central configuration, deployment, upgrades and fleet health; you can also deploy with Group Policy, Intune or Configuration Manager.
Reduce at the source
Why not use Splunk Edge Processor or Ingest Actions?
Both cut what gets indexed. The difference is where the work happens.
Edge Processor and Ingest Actions work on the Splunk side: on a processing tier between forwarders and indexers, or in the indexing pipeline. By then the data has left the Windows host, and each host still needs a forwarder. DPLens reduces and masks on the host, before anything is cached or sent, and can deliver to Splunk and another receiver at the same time.
- Reduction and masking happen before data leaves the host.
- The same agent can send Windows data to Splunk and to any other SIEM or collector you run.
- You get an agent you can review: signed, with an SBOM and no call-home.
Secure by design
An agent you can defend in a security review.
FAQ
Questions Splunk teams ask
Does Splunk see DPLens as a forwarder?
It speaks the forwarder protocol, and its handshake advertises this host's name by default, as a UF does. Events land on the index and sourcetype you configure.
Will my existing searches, dashboards and apps keep working?
Yes, when the index, sourcetype and event format match what they were written against. That is why the procedure runs DPLens alongside the UF and compares what arrives before anything is switched off.
Can I send to Splunk and another SIEM at the same time?
Yes. One pipeline delivers to several destinations at once, such as Splunk and a syslog SIEM or an OpenTelemetry Collector. Each destination has its own queue, so an outage at one leaves the others flowing.
Is there an equivalent of the deployment server?
Yes: DPLens Manager, for central configuration, fleet health monitoring, deployment and upgrades. It is self-hosted, air-gap capable and included in every subscription. Agents can also be deployed with Group Policy, Intune or Configuration Manager.
How is it licensed?
With an offline, signed key bound to one machine or to one or more Active Directory domains. There is no per-GB cost, so filtering more never costs you more. See the licensing model.
See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.