Windows Event Log collection

A Windows Event Log collection agent that filters before your SIEM pays for it.

Collect Security, System, Application, Sysmon, PowerShell and any custom channel from one source. Filter at the channel with XPath, resume from a checkpoint after a restart, and deliver straight to your SIEM over syslog, Snare, NDJSON, the Splunk protocols or OpenTelemetry (OTLP/HTTP).

  • Security
  • Sysmon
  • PowerShell
  • Custom channels
  • XPath

In short

DPLens is a Windows Event Log collection agent: it reads Security, Sysmon and any other channel on each machine, filters at the source so only the Event IDs you need are collected, and delivers directly to your SIEM. Collection resumes exactly where it left off after a restart. Compared with Windows Event Forwarding, there is no collector tier to build, and filters can test each event's content as well as its ID.

What it collects

Which Windows event logs can DPLens collect?

Any channel on the machine. DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows, and its Windows Event Log source is a list of channels: Security, System and Application alongside Applications and Services logs such as Sysmon and PowerShell, kept in step by one source.

01

Channel subscriptions

Pick from the offered channels or use More channels to choose any channel on the machine, including custom application logs and Microsoft-Windows-Sysmon/Operational. Reading the Security channel works out of the box, with no extra Group Policy change.

02

Filtering at the source

Choose a severity (all, Warning and above, or Errors only), Event IDs to include or exclude (ranges allowed), and named providers, or supply your own XPath query, with per-channel overrides. Only the events you want are collected.

03

Resumes where it left off

After a restart, an upgrade or a pause, collection resumes exactly where it stopped, with nothing re-read or skipped. While a source is paused, Windows keeps the events in its own log.

04

New events or the backlog

By default a source collects new events only. Turn on Also read existing events to take a channel's history once, when you are backfilling.

Finding the right channels is quick. The add-source wizard offers templates (Windows security essentials, IIS, DNS query, DHCP audit, SQL Server error and Exchange logs), each saying what it reads and telling you when a log needs switching on in Windows first. The Recommendations page scans the machine's roles, services, disks and audit policy locally, sends nothing anywhere, and ranks what is worth collecting.

Filtering

Should I filter at the source or in the pipeline?

The cheapest event is the one you never read. The next cheapest is the one you read and never send.

Source filter compared with pipeline filter
WhereWhat it can testUse it for
At the channel (source)Severity, Event ID include and exclude lists, provider, or a raw XPath queryA whole Event ID, level or provider you never want. Only the events you want are collected.
In the pipeline (filter stage)Any field: equals, contains, pattern, one of a list, inside a CIDR range, greater or less than, combined however you needDropping part of an Event ID: one service account, one process, loopback traffic, machine accounts ending in $.

Content-level rules belong in the pipeline, where they can test any field of any event. The same pipeline can collapse repeats into one event with a count, mask sensitive values, normalise to CIM or OCSF field names, and cap what leaves a noisy machine. See SIEM cost reduction for how those add up, and the guide to noisy Windows Security Event IDs for which IDs to tackle first.

Event shape

Structured fields, rendered text or raw XML

Send each event in the shape your receiver expects, from compact structured fields to the full message text.

Event shapes from a Windows Event Log source
OptionWhat you get
Structured fields (default)The event's fields, in their most compact form.
With message textThe fields plus the event's human-readable message.
SnareThe message text plus the task name that fills a Snare collector's category column.
Classic Windows formThe message text plus the flattened Windows-event form Splunk searches are often written against.

On a Splunk destination, choose the classic flattened form or the raw event XML. NDJSON keeps every field as a named field and preserves the most.

Built for throughput

In our lab benchmark, DPLens delivered more than 30× the throughput of the established Windows agents we tested, at about a tenth of the CPU per event. Lab figures, not a guarantee: real throughput depends on hardware, sources and pipeline rules.

More than 30×the throughput, in our lab benchmark
About a tenthof the CPU per event

Windows Event Forwarding alternative

How does DPLens compare with Windows Event Forwarding?

Windows Event Forwarding (WEF) is built into Windows. The difference is where the work happens: DPLens filters, shapes and delivers on each host, with no collector tier in between.

Windows Event Forwarding and DPLens, side by side
QuestionWEF with a Windows Event CollectorDPLens
No collector tierNo – one or more collector servers to build, size and keep runningYes – an agent on each machine delivers directly
Direct delivery to the SIEMNo – something else on the collector has to read Forwarded Events and ship themYes – syslog, Snare, NDJSON, Splunk S2S or HEC, or OTLP/HTTP to an OpenTelemetry Collector
Filtering on event contentPartly – XPath in the subscription: Event ID, level, provider and exact field matchesYes – XPath at the channel, then pipeline rules on content: contains, patterns, CIDR, comparisons
Aggregation, masking, normalisationNo – not part of WEFYes – on the host, before anything is cached or sent
TransportWinRM, Kerberos in a domainUDP, TCP or TLS to your receiver; certificate validation on by default
ConfigurationGroup Policy and subscriptions on the collectorDPLens Manager for central configuration, deployment, upgrades and fleet health; or Group Policy, Intune and Configuration Manager

Deployment and delivery

How do I roll it out across an estate?

One executable and its installer, with no .NET, Java, Visual C++ redistributable or database to install and no internet access needed. DPLens Manager, self-hosted and included in every subscription, takes care of the fleet.

  1. Configure one machine

    Use the local console and its recommendations to build the sources, pipeline and destination you want, and prove the path with a test event.

  2. Manage it centrally

    Manage the configuration centrally in DPLens Manager, with fleet health monitoring across every agent. It is self-hosted and air-gap capable.

  3. Deploy with the tools you prefer

    Roll out with DPLens Manager, or package the configured machine with your licence key, configuration, certificates and credentials into one installer for Group Policy, Intune or Configuration Manager.

  4. Pilot, then roll out

    Deploy to a pilot group first, then to the whole estate with the same configuration. Golden-image clones prepared with sysprep start with clean working state at first start, and upgrades follow through DPLens Manager.

Each destination has its own disk-backed queue, so an outage queues events rather than discarding them, and every drop is counted. See SIEM integrations for Splunk, QRadar, Securonix, Devo, Secureworks Taegis and syslog or Snare receivers, and OpenTelemetry for an OTLP endpoint.

Secure by design

An agent you can defend in a security review.

Signed and verifiableEvery release is signed and ships with checksums and a software bill of materials, so you can verify it before it reaches a server.
Nothing calls homeNo telemetry, no licence server and no automatic updates. Your data goes only where you send it.
Secure engineeringBuilt and tested to modern secure-development practice, for software that runs on your most sensitive servers.
Least privilegeRuns with only the access it needs, with administration kept apart from collection.

FAQ

Questions buyers ask

Can DPLens forward Sysmon logs?

Yes. Add Microsoft-Windows-Sysmon/Operational to a Windows Event Log source, alone or alongside Security and other channels. DPLens collects the channel, and you keep full control of Sysmon's own configuration.

Do I need WinRM, WEF or a collector server?

No. DPLens reads the event logs locally and connects outbound to the destinations you configure. Inbound, only the local console listens by default, plus any syslog or NetFlow receiver you choose to add.

What happens to events while the agent is stopped or upgrading?

Windows keeps writing them to its own logs, within the channel's retention, and DPLens resumes exactly where it left off. Upgrades keep configuration, licence, secrets, positions and cache.

Can I use my own XPath query?

Yes. Supply a raw XPath query on the source in place of the typed filters.

How do we manage DPLens across hundreds of servers?

With DPLens Manager: central configuration, fleet health monitoring, deployment and upgrades. It is self-hosted, air-gap capable and included in every subscription. Agents can also be deployed with Group Policy, Intune or Configuration Manager.

Which Windows versions are supported?

Windows Server 2025, 2022, 2019 and 2016, and Windows 11 and 10, on x64. Server Core is supported, with the console reached from a browser on another machine.

Related

Last reviewed 1 October 2026 against the DPLens 1.0 documentation. Splunk and Snare are trademarks of their respective owners; DPLens is not affiliated with or endorsed by either. Windows and Sysmon are trademarks of Microsoft.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.