Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

The steps below recommend initial settings for Snare Agents. As dedicated tables exist for all of the agents mentioned below, the standard syslog systems must not be used (this will ensure the correct handling of data by the Snare Central). The use of the Snare via the web user interface (UI) is recommended (the user friendly interface will maintain the appropriate syntax and formatting) and instructions to enable this service will be detailed where applicable.

...

For all UNIX-based agents, the following section should be included in the configuration file to enable remote control capabilities. The user friendly interface will maintain the appropriate syntax and formatting of the Snare configuration files, while also allowing the Snare Central to contact its agents to check their individual configuration settings.

...

  1. Specify the log files that Epilog should monitor.
  2. Set the destination server to the Snare Central IP address or hostname.
  3. Syslog option must not be used when sending logs to a Snare Central so that all events are processed correctly by the Snare Central.
  4. Send event to TCP or UDP port 6161.
  5. UDP is recommended for faster and more efficient use of host and network resources.
  6. Generally, events will be stored in the Snare Central GenericLog table.

...