Windows Event Log collection
A Windows Event Log collection agent that filters before your SIEM pays for it.
Collect Security, System, Application, Sysmon, PowerShell and any custom channel from one source. Filter at the channel with XPath, resume from a checkpoint after a restart, and deliver straight to your SIEM over syslog, Snare, NDJSON, the Splunk protocols or OpenTelemetry (OTLP/HTTP).
- Security
- Sysmon
- PowerShell
- Custom channels
- XPath
In short
DPLens is a Windows Event Log collection agent: it reads Security, Sysmon and any other channel on each machine, filters at the source so only the Event IDs you need are collected, and delivers directly to your SIEM. Collection resumes exactly where it left off after a restart. Compared with Windows Event Forwarding, there is no collector tier to build, and filters can test each event's content as well as its ID.
What it collects
Which Windows event logs can DPLens collect?
Any channel on the machine. DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows, and its Windows Event Log source is a list of channels: Security, System and Application alongside Applications and Services logs such as Sysmon and PowerShell, kept in step by one source.
01
Channel subscriptions
Pick from the offered channels or use More channels to choose any channel on the machine, including custom application logs and Microsoft-Windows-Sysmon/Operational. Reading the Security channel works out of the box, with no extra Group Policy change.
02
Filtering at the source
Choose a severity (all, Warning and above, or Errors only), Event IDs to include or exclude (ranges allowed), and named providers, or supply your own XPath query, with per-channel overrides. Only the events you want are collected.
03
Resumes where it left off
After a restart, an upgrade or a pause, collection resumes exactly where it stopped, with nothing re-read or skipped. While a source is paused, Windows keeps the events in its own log.
04
New events or the backlog
By default a source collects new events only. Turn on Also read existing events to take a channel's history once, when you are backfilling.
Finding the right channels is quick. The add-source wizard offers templates (Windows security essentials, IIS, DNS query, DHCP audit, SQL Server error and Exchange logs), each saying what it reads and telling you when a log needs switching on in Windows first. The Recommendations page scans the machine's roles, services, disks and audit policy locally, sends nothing anywhere, and ranks what is worth collecting.
Filtering
Should I filter at the source or in the pipeline?
The cheapest event is the one you never read. The next cheapest is the one you read and never send.
| Where | What it can test | Use it for |
|---|---|---|
| At the channel (source) | Severity, Event ID include and exclude lists, provider, or a raw XPath query | A whole Event ID, level or provider you never want. Only the events you want are collected. |
| In the pipeline (filter stage) | Any field: equals, contains, pattern, one of a list, inside a CIDR range, greater or less than, combined however you need | Dropping part of an Event ID: one service account, one process, loopback traffic, machine accounts ending in $. |
Content-level rules belong in the pipeline, where they can test any field of any event. The same pipeline can collapse repeats into one event with a count, mask sensitive values, normalise to CIM or OCSF field names, and cap what leaves a noisy machine. See SIEM cost reduction for how those add up, and the guide to noisy Windows Security Event IDs for which IDs to tackle first.
Event shape
Structured fields, rendered text or raw XML
Send each event in the shape your receiver expects, from compact structured fields to the full message text.
| Option | What you get |
|---|---|
| Structured fields (default) | The event's fields, in their most compact form. |
| With message text | The fields plus the event's human-readable message. |
| Snare | The message text plus the task name that fills a Snare collector's category column. |
| Classic Windows form | The message text plus the flattened Windows-event form Splunk searches are often written against. |
On a Splunk destination, choose the classic flattened form or the raw event XML. NDJSON keeps every field as a named field and preserves the most.
Built for throughput
In our lab benchmark, DPLens delivered more than 30× the throughput of the established Windows agents we tested, at about a tenth of the CPU per event. Lab figures, not a guarantee: real throughput depends on hardware, sources and pipeline rules.
Windows Event Forwarding alternative
How does DPLens compare with Windows Event Forwarding?
Windows Event Forwarding (WEF) is built into Windows. The difference is where the work happens: DPLens filters, shapes and delivers on each host, with no collector tier in between.
| Question | WEF with a Windows Event Collector | DPLens |
|---|---|---|
| No collector tier | No – one or more collector servers to build, size and keep running | Yes – an agent on each machine delivers directly |
| Direct delivery to the SIEM | No – something else on the collector has to read Forwarded Events and ship them | Yes – syslog, Snare, NDJSON, Splunk S2S or HEC, or OTLP/HTTP to an OpenTelemetry Collector |
| Filtering on event content | Partly – XPath in the subscription: Event ID, level, provider and exact field matches | Yes – XPath at the channel, then pipeline rules on content: contains, patterns, CIDR, comparisons |
| Aggregation, masking, normalisation | No – not part of WEF | Yes – on the host, before anything is cached or sent |
| Transport | WinRM, Kerberos in a domain | UDP, TCP or TLS to your receiver; certificate validation on by default |
| Configuration | Group Policy and subscriptions on the collector | DPLens Manager for central configuration, deployment, upgrades and fleet health; or Group Policy, Intune and Configuration Manager |
Deployment and delivery
How do I roll it out across an estate?
One executable and its installer, with no .NET, Java, Visual C++ redistributable or database to install and no internet access needed. DPLens Manager, self-hosted and included in every subscription, takes care of the fleet.
Configure one machine
Use the local console and its recommendations to build the sources, pipeline and destination you want, and prove the path with a test event.
Manage it centrally
Manage the configuration centrally in DPLens Manager, with fleet health monitoring across every agent. It is self-hosted and air-gap capable.
Deploy with the tools you prefer
Roll out with DPLens Manager, or package the configured machine with your licence key, configuration, certificates and credentials into one installer for Group Policy, Intune or Configuration Manager.
Pilot, then roll out
Deploy to a pilot group first, then to the whole estate with the same configuration. Golden-image clones prepared with sysprep start with clean working state at first start, and upgrades follow through DPLens Manager.
Each destination has its own disk-backed queue, so an outage queues events rather than discarding them, and every drop is counted. See SIEM integrations for Splunk, QRadar, Securonix, Devo, Secureworks Taegis and syslog or Snare receivers, and OpenTelemetry for an OTLP endpoint.
Secure by design
An agent you can defend in a security review.
How to do it
In the documentation
- Adding a Windows Event Log source: channels, severity, Event IDs and rendering
- Windows Event Log source reference: queries and event shapes
- Collecting several channels at once
- Recommendations: what this machine has that is worth collecting
- Deployment options: Group Policy, Intune, Configuration Manager and golden images
- Requirements: Windows versions, ports and permissions
FAQ
Questions buyers ask
Can DPLens forward Sysmon logs?
Yes. Add Microsoft-Windows-Sysmon/Operational to a Windows Event Log source, alone or alongside Security and other channels. DPLens collects the channel, and you keep full control of Sysmon's own configuration.
Do I need WinRM, WEF or a collector server?
No. DPLens reads the event logs locally and connects outbound to the destinations you configure. Inbound, only the local console listens by default, plus any syslog or NetFlow receiver you choose to add.
What happens to events while the agent is stopped or upgrading?
Windows keeps writing them to its own logs, within the channel's retention, and DPLens resumes exactly where it left off. Upgrades keep configuration, licence, secrets, positions and cache.
Can I use my own XPath query?
Yes. Supply a raw XPath query on the source in place of the typed filters.
How do we manage DPLens across hundreds of servers?
With DPLens Manager: central configuration, fleet health monitoring, deployment and upgrades. It is self-hosted, air-gap capable and included in every subscription. Agents can also be deployed with Group Policy, Intune or Configuration Manager.
Which Windows versions are supported?
Windows Server 2025, 2022, 2019 and 2016, and Windows 11 and 10, on x64. Server Core is supported, with the console reached from a browser on another machine.
Related
Where to go next
See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.