Snare Central can process a reasonably wide range of source data types. The Snare Central data acquisition software is generally tuned for particular versions of operating system or device logs, so if you encounter problems importing particular types of data, please contact your Snare Central support team, and be prepared to supply (sanitised if required) log samples.
Snort Sensor
Organisations that use the Snort network intrusion detection system can send data to Snare Central via the syslog protocol. Snare will be able to collect, interpret, and report on the events. The following information provides an overview of the steps required to configure the Snort sensor to send eventlog data back to Snare Central. Note that there is no configuration required on Snare Central.
...
Tip |
---|
|
On the host that is acting as a Snort collection sensor: - In the file /etc/syslog.conf, add the following two lines:
# Send all SYSLOG events to Snare Central
*.*@12.23.34.45
- Please substitute the IP address, or the DNS name, of Snare Central for the string "12.23.34.45"
- Modify the file /etc/snort/snort.conf to include the following line:
output alert_syslog: LOG_AUTH LOG_ALERT
- An existing (or possibly, multiple) 'output' line may already exist in the file - that is acceptable. Snort will be able to send output to both targets.
- Restart your snort network intrusion detection system and syslog daemon. Depending on your distribution this may be one of:
/etc/init.d/snortd; /etc/init.d/syslog restart service snortd restart; service syslog restart
|
Troubleshooting Snort
Checking for Snort Sensor errors:
- Look in
/var/log/messages
for errors. - Run manually:
/usr/sbin/snort -D -i "ppp0" -c /etc/snort/snort.conf
- ..then look in
/var/log/messages
for errors
Collecting ACF2 Data
Snare Central is able to collect ACF2 processed reports, via FTP transfer. The processed reports need to be transferred to a particular directory on Snare Central, which will then be uploaded by Snare Central processes, on a daily basis.
...
Code Block |
---|
title | CSCSNR01 |
---|
linenumbers | true |
---|
|
********************************** Top of Data **********************************
//CSCSNR01 JOB (P,SCF81),ACT.SECURITY,CLASS=C,MSGCLASS=J
/*JOBPARM SYSAFF=PROD
//-----------------------------------------------------------------
//*
//* JOB TO PRODUCE ACF2 LIDMOD REPORT FOR XFER TO SNARE SERVER
//*
//*---------- DELETE TEMP XFER LIB ---------------------------------
//*
//STEP1 EXEC PGM=IKJEFT01,REGION=8192K
//SYSPRINT DD SYSOUT=*
//SYSTSPRT DD SYSOUT=*
//SYSTERM DD SYSOUT=*
//SYSUDUMP DD SYSOUT=*
//SYSTSIN DD *
DELETE 'CSC.SNARE01.LIDMODS.XFER'
//*
//*---------- ACF2 LID DB MODIFICATION LOG REPORT ------------------
//*
//STEP2 EXEC PGM=ACFRPTLL
//SYSPRINT DD DSN=CSC.SNARE01.LIDMODS.REPORT(+1),
//
DISP=(,CATLG),
//
VOL=SER=BTCH52,
//
UNIT=SYSDA,
//
SPACE=(TRK,(60,5),RLSE),
//
DCB=(GDGMODEL,RECFM=FB,LRECL=142,BLKSIZE=27974)
//SYSUDUMP DD SYSOUT=*
//REC01 DD DSN=CTF.SMFJR,DISP=SHR
//SYSIN DD *
MASK(********)
DETAIL
NOUPDATE
SYSID(****)
//*
//*---------- COPY REPORT FROM GDG TO XFER LIB ---------------------
//*
//COPY
EXEC PGM=IEBGENER
//SYSPRINT DD SYSOUT=*
//SYSUT1
DD DSN=CSC.SNARE01.LIDMODS.REPORT(+1),
DISP=SHR
//SYSUT2
DD DSN=CSC.SNARE01.LIDMODS.XFER,
//
DISP=(NEW,CATLG,DELETE),
//
VOL=SER=BTCH52,
//
UNIT=SYSDA,
//
SPACE=(TRK,(60,5),RLSE),
//
DCB=*.SYSUT1
//*
DCB=(RECFM=FB,LRECL=142,BLKSIZE=27974)
//SYSIN
DD DUMMY
//*
//*---------- FTP XFER FILE TO SNARE SERVER ------------------------
//*
//STEP4 EXEC FTP,
//
SERVER='CSCSNARE',
//
FTPUSER='SNAREXFER',
//
FTPCMDS='CSCSNR01',
//
ENV='PROD',
//
SOUT='*'
//*
//*---------- Notify Security Monitoring Team if job fails ---------
//*
//*JOBFAIL IF ((RC > 4) | (ABEND)) THEN
//*
//SENDMEMO EXEC PGM=IEBGENER
//SYSPRINT DD SYSOUT=*
//SYSUT1 DD *
HELO NCC
MAIL FROM:<PSC0SCHD@AGENCY.COM>
RCPT TO:<ITSECMON@AGENCY.COM>
DATA
TO:ITSECMON<ITSECMON@AGENCY.COM>
SUBJECT:SNARE REPORT FTP JOB FAILURE: JOB CSCSNR01
PLEASE CHECK SDSF OUTPUT FOR THIS JOB ASAP AND DETERMINE WHY.
>> THIS E-MAIL IS GENERATED BY A BATCH JOB RUNNING ON THE
>> AGENCY'S MAINFRAME ENVIRONMENT.
.
QUIT
/*
//SYSUT2 DD SYSOUT=(B,SMTP)
//SYSIN DD DUMMY
//*
//JOBFAIL ENDIF
//*===================================================================
|
RACF Violation Logs
RACF resource violation logs can be batch-imported to Snare Central. In particular, ACCESS, DELRES, and JOBINIT logs are supported directly, .
...
Info |
---|
|
RACF logs are fixed-column logs. Snare Central assumes the following format: - EVENT TYPE: Characters 1-8
- EVENT QUALIFIER: Characters 10-17 (Eg; SUCCESS, INVPSWD, RACINITD)
- TIME: Characters 19-26
- DATE: Characters 28-37
- SYSTEM: Characters 39-42 (SYSTEM ID)
- USER ID: Characters 59-66
- GROUP ID: Characters 68-75
- TERMINAL (HOSTNAME): Characters 171-178
- JOB NAME: Characters 180-187
- USER NAME: Characters 556-575
- ATTRIBUTES: (True/False)
- VIOLATION: 44-47
- BYPASS: 107-110
- SPECIAL USER: 602-605
- PRIV: 646-649
|
Tandem Logs
Tandom systems supply logs with the following fields:
...
Logs should be transferred to the directory /data/SnareCollect/TandemLog via FTP using the user 'snarexfer'. Logs will be processed daily, at around midnight.
Sidewinder Firewall Logs
Sidewinder firewall logs can be exported to CSV, and transferred to Snare Central for processing.
...
Logs should be transferred to the directory /data/SnareCollect/SidewinderLog via FTP using the user 'snarexfer'. Logs will be processed daily, at around midnight.
Content Keeper Logs
Content keeper logs can be transferred to the directory /data/SnareCollect/CKeeperLog via FTP using the user 'snarexfer'. Logs will be processed daily, at around midnight.
...
- Date/Time
- Ignored field
- Source IP Address
- User Name
- Bytes
- Status Code
- Content
- URL
- Policy
- Category
Checkpoint Firewall1 Logs
Checkpoint Firewall 1 firewalls can export log data to a CSV file. Snare is capable of coping with a range of formats, as long as the header line, specifying the log format, is included as the first line in each exported file.
...
Checkpoint Firewall logs can be transferred to the directory /data/SnareCollect/Firewall1Log via FTP using the user 'snarexfer'. Logs will be processed daily, at around midnight.
Gauntlet Firewall Logs
Gauntlet Firewall logs can be transferred to the directory /data/SnareCollect/GauntletFirewallLog/ via FTP using the user 'snarexfer'. Logs will be processed daily, at around midnight.
Content is assumed to be in ASCII format, and values are space separated.
OS400 Logs
OS400 logs can be transferred to the directory /data/SnareCollect/OS400Log via FTP using the user 'snarexfer'. Logs will be processed daily, at around midnight.
...
- Journal Code (JournalCode)
- Journal Entry Code (JournalEntryCode)
- Journal Entry Date (Date)
- Journal Entry Time (Time)
- System name (System)
- Job Name (JobName)
- User Name (JobUser)
- Job Number (JobNumber)
- Program Accessing Object (Program)
- Object Failure Object Name (OFName)
- Object Failure Library Name (OFLibrary)
- Object Failure Object Type (OFType)
- Failed Login User (Strings)
- Failed Login Job (Strings)
- System Value name (Strings)
- Changed Value (Strings)
Squid Proxy Logs
Squid proxy logs (in the default squid log format) can be transferred to the directory /data/SnareCollect/SquidProxyLog via FTP using the user 'snarexfer'. Logs will be processed daily, at around midnight.
Apache Logs
Apache web server logs (in the default apache 'combined' format) can be transferred to the directory /data/SnareCollect/ApacheLog via FTP using the user 'snarexfer'. Logs will be processed daily, at around midnight.
IIS web server logs can be transferred to the directory /data/SnareCollect/IISWebLog via FTP using the user 'snarexfer'. Logs will be processed daily, at around midnight.
...
- date
- time
- s-ip
- cs-method
- cs-uri-stem
- cs-uri-query
- s-port
- cs-username
- c-ip
- cs(User-Agent)
- sc-status
- sc-substatus
- sc-win32-status
Windows Event Logs (Exported from Snare Agents)
Snare for Windows agents are capable of exporting log data to a file on disk, rather than pushing the events back to a central server.
...
Logs should be in standard Snare Agent tab-delimited text format, and can be transferred to the directory /data/SnareCollect/MSWinEventLog via FTP using the user 'snarexfer'. Logs will be processed daily, at around midnight.
Windows Event Logs (EVTX files)
Note: Only available in Snare Central version 7.1 or newer
...
Info |
---|
|
The following Time Zones are supported: Africa:Abidjan | Africa:Accra | Africa:Addis_Ababa | Africa:Algiers | Africa:Asmara | Africa:Asmera | Africa:Bamako | Africa:Bangui | Africa:Banjul | Africa:Bissau | Africa:Blantyre | Africa:Brazzaville | Africa:Bujumbura | Africa:Cairo | Africa:Casablanca | Africa:Ceuta | Africa:Conakry | Africa:Dakar | Africa:Dar_es_Salaam | Africa:Djibouti | Africa:Douala | Africa:El_Aaiun | Africa:Freetown | Africa:Gaborone | Africa:Harare | Africa:Johannesburg | Africa:Juba | Africa:Kampala | Africa:Khartoum | Africa:Kigali | Africa:Kinshasa | Africa:Lagos | Africa:Libreville | Africa:Lome | Africa:Luanda | Africa:Lubumbashi | Africa:Lusaka | Africa:Malabo | Africa:Maputo | Africa:Maseru | Africa:Mbabane | Africa:Mogadishu | Africa:Monrovia | Africa:Nairobi | Africa:Ndjamena | Africa:Niamey | Africa:Nouakchott | Africa:Ouagadougou | Africa:Porto-Novo | Africa:Sao_Tome | Africa:Timbuktu | Africa:Tripoli | Africa:Tunis | Africa:Windhoek |
| America:Adak | America:Anchorage | America:Anguilla | America:Antigua | America:Araguaina | America:Argentina:Buenos_Aires | America:Argentina:Catamarca | America:Argentina:ComodRivadavia | America:Argentina:Cordoba | America:Argentina:Jujuy | America:Argentina:La_Rioja | America:Argentina:Mendoza | America:Argentina:Rio_Gallegos | America:Argentina:Salta | America:Argentina:San_Juan | America:Argentina:San_Luis | America:Argentina:Tucuman | America:Argentina:Ushuaia | America:Aruba | America:Asuncion | America:Atikokan | America:Atka | America:Bahia | America:Bahia_Banderas | America:Barbados | America:Belem | America:Belize | America:Blanc-Sablon | America:Boa_Vista | America:Bogota | America:Boise | America:Buenos_Aires | America:Cambridge_Bay | America:Campo_Grande | America:Cancun | America:Caracas | America:Catamarca | America:Cayenne | America:Cayman | America:Chicago | America:Chihuahua | America:Coral_Harbour | America:Cordoba | America:Costa_Rica | America:Creston | America:Cuiaba | America:Curacao | America:Danmarkshavn | America:Dawson | America:Dawson_Creek | America:Denver | America:Detroit | America:Dominica | America:Edmonton | America:Eirunepe | America:El_Salvador | America:Ensenada | America:Fort_Wayne | America:Fortaleza | America:Glace_Bay | America:Godthab | America:Goose_Bay | America:Grand_Turk | America:Grenada | America:Guadeloupe | America:Guatemala | America:Guayaquil | America:Guyana | America:Halifax | America:Havana | America:Hermosillo | America:Indiana:Indianapolis | America:Indiana:Knox | America:Indiana:Marengo | America:Indiana:Petersburg | America:Indiana:Tell_City | America:Indiana:Vevay | America:Indiana:Vincennes | America:Indiana:Winamac | America:Indianapolis | America:Inuvik | America:Iqaluit | America:Jamaica | America:Jujuy | America:Juneau | America:Kentucky:Louisville | America:Kentucky:Monticello | America:Knox_IN | America:Kralendijk | America:La_Paz | America:Lima | America:Los_Angeles | America:Louisville | America:Lower_Princes | America:Maceio | America:Managua | America:Manaus | America:Marigot | America:Martinique | America:Matamoros | America:Mazatlan | America:Mendoza | America:Menominee | America:Merida | America:Metlakatla | America:Mexico_City | America:Miquelon | America:Moncton | America:Monterrey | America:Montevideo | America:Montreal | America:Montserrat | America:Nassau | America:New_York | America:Nipigon | America:Nome | America:Noronha | America:North_Dakota:Beulah | America:North_Dakota:Center | America:North_Dakota:New_Salem | America:Ojinaga | America:Panama | America:Pangnirtung | America:Paramaribo | America:Phoenix | America:Port-au-Prince | America:Port_of_Spain | America:Porto_Acre | America:Porto_Velho | America:Puerto_Rico | America:Rainy_River | America:Rankin_Inlet | America:Recife | America:Regina | America:Resolute | America:Rio_Branco | America:Rosario | America:Santa_Isabel | America:Santarem | America:Santiago | America:Santo_Domingo | America:Sao_Paulo | America:Scoresbysund | America:Shiprock | America:Sitka | America:St_Barthelemy | America:St_Johns | America:St_Kitts | America:St_Lucia | America:St_Thomas | America:St_Vincent | America:Swift_Current | America:Tegucigalpa | America:Thule | America:Thunder_Bay | America:Tijuana | America:Toronto | America:Tortola | America:Vancouver | America:Virgin | America:Whitehorse | America:Winnipeg | America:Yakutat | America:Yellowknife |
| Antarctica:Casey | Antarctica:Davis | Antarctica:DumontDUrville | Antarctica:Macquarie | Antarctica:Mawson | Antarctica:McMurdo | Antarctica:Palmer | Antarctica:Rothera | Antarctica:South_Pole | Antarctica:Syowa | Antarctica:Troll | Antarctica:Vostok |
|
|
| Arctic:Longyearbyen |
|
|
|
| Asia:Aden | Asia:Almaty | Asia:Amman | Asia:Anadyr | Asia:Aqtau | Asia:Aqtobe | Asia:Ashgabat | Asia:Ashkhabad | Asia:Baghdad | Asia:Bahrain | Asia:Baku | Asia:Bangkok | Asia:Beirut | Asia:Bishkek | Asia:Brunei | Asia:Calcutta | Asia:Chita | Asia:Choibalsan | Asia:Chongqing | Asia:Chungking | Asia:Colombo | Asia:Dacca | Asia:Damascus | Asia:Dhaka | Asia:Dili | Asia:Dubai | Asia:Dushanbe | Asia:Gaza | Asia:Harbin | Asia:Hebron | Asia:Ho_Chi_Minh | Asia:Hong_Kong | Asia:Hovd | Asia:Irkutsk | Asia:Istanbul | Asia:Jakarta | Asia:Jayapura | Asia:Jerusalem | Asia:Kabul | Asia:Kamchatka | Asia:Karachi | Asia:Kashgar | Asia:Kathmandu | Asia:Katmandu | Asia:Khandyga | Asia:Kolkata | Asia:Krasnoyarsk | Asia:Kuala_Lumpur | Asia:Kuching | Asia:Kuwait | Asia:Macao | Asia:Macau | Asia:Magadan | Asia:Makassar | Asia:Manila | Asia:Muscat | Asia:Nicosia | Asia:Novokuznetsk | Asia:Novosibirsk | Asia:Omsk | Asia:Oral | Asia:Phnom_Penh | Asia:Pontianak | Asia:Pyongyang | Asia:Qatar | Asia:Qyzylorda | Asia:Rangoon | Asia:Riyadh | Asia:Saigon | Asia:Sakhalin | Asia:Samarkand | Asia:Seoul | Asia:Shanghai | Asia:Singapore | Asia:Srednekolymsk | Asia:Taipei | Asia:Tashkent | Asia:Tbilisi | Asia:Tehran | Asia:Tel_Aviv | Asia:Thimbu | Asia:Thimphu | Asia:Tokyo | Asia:Ujung_Pandang | Asia:Ulaanbaatar | Asia:Ulan_Bator | Asia:Urumqi | Asia:Ust-Nera | Asia:Vientiane | Asia:Vladivostok | Asia:Yakutsk | Asia:Yekaterinburg | Asia:Yerevan |
|
| Atlantic:Azores | Atlantic:Bermuda | Atlantic:Canary | Atlantic:Cape_Verde | Atlantic:Faeroe | Atlantic:Faroe | Atlantic:Jan_Mayen | Atlantic:Madeira | Atlantic:Reykjavik | Atlantic:South_Georgia | Atlantic:St_Helena | Atlantic:Stanley |
|
|
| Australia:ACT | Australia:Adelaide | Australia:Brisbane | Australia:Broken_Hill | Australia:Canberra | Australia:Currie | Australia:Darwin | Australia:Eucla | Australia:Hobart | Australia:LHI | Australia:Lindeman | Australia:Lord_Howe | Australia:Melbourne | Australia:North | Australia:NSW | Australia:Perth | Australia:Queensland | Australia:South | Australia:Sydney | Australia:Tasmania | Australia:Victoria | Australia:West | Australia:Yancowinna |
|
| Europe:Amsterdam | Europe:Andorra | Europe:Athens | Europe:Belfast | Europe:Belgrade | Europe:Berlin | Europe:Bratislava | Europe:Brussels | Europe:Bucharest | Europe:Budapest | Europe:Busingen | Europe:Chisinau | Europe:Copenhagen | Europe:Dublin | Europe:Gibraltar | Europe:Guernsey | Europe:Helsinki | Europe:Isle_of_Man | Europe:Istanbul | Europe:Jersey | Europe:Kaliningrad | Europe:Kiev | Europe:Lisbon | Europe:Ljubljana | Europe:London | Europe:Luxembourg | Europe:Madrid | Europe:Malta | Europe:Mariehamn | Europe:Minsk | Europe:Monaco | Europe:Moscow | Europe:Nicosia | Europe:Oslo | Europe:Paris | Europe:Podgorica | Europe:Prague | Europe:Riga | Europe:Rome | Europe:Samara | Europe:San_Marino | Europe:Sarajevo | Europe:Simferopol | Europe:Skopje | Europe:Sofia | Europe:Stockholm | Europe:Tallinn | Europe:Tirane | Europe:Tiraspol | Europe:Uzhgorod | Europe:Vaduz | Europe:Vatican | Europe:Vienna | Europe:Vilnius | Europe:Volgograd | Europe:Warsaw | Europe:Zagreb | Europe:Zaporozhye | Europe:Zurich |
| Indian:Antananarivo | Indian:Chagos | Indian:Christmas | Indian:Cocos | Indian:Comoro | Indian:Kerguelen | Indian:Mahe | Indian:Maldives | Indian:Mauritius | Indian:Mayotte | Indian:Reunion |
|
|
|
| Pacific:Apia | Pacific:Auckland | Pacific:Bougainville | Pacific:Chatham | Pacific:Chuuk | Pacific:Easter | Pacific:Efate | Pacific:Enderbury | Pacific:Fakaofo | Pacific:Fiji | Pacific:Funafuti | Pacific:Galapagos | Pacific:Gambier | Pacific:Guadalcanal | Pacific:Guam | Pacific:Honolulu | Pacific:Johnston | Pacific:Kiritimati | Pacific:Kosrae | Pacific:Kwajalein | Pacific:Majuro | Pacific:Marquesas | Pacific:Midway | Pacific:Nauru | Pacific:Niue | Pacific:Norfolk | Pacific:Noumea | Pacific:Pago_Pago | Pacific:Palau | Pacific:Pitcairn | Pacific:Pohnpei | Pacific:Ponape | Pacific:Port_Moresby | Pacific:Rarotonga | Pacific:Saipan | Pacific:Samoa | Pacific:Tahiti | Pacific:Tarawa | Pacific:Tongatapu | Pacific:Truk | Pacific:Wake | Pacific:Wallis | Pacific:Yap |
|
|
|
Lotus Notes / Domino
Snare Central is able to connect to a Domino server to retrieve eventlog data from log.nsf. It can also retrieve user and group information, plus access controls. However, some of the default settings in Lotus Domino can cause problems with the Snare Agent; please modify the server as follows: From the Domino Administrator page, click the Configuration tab, expand the Web section and click Internet Sites.
...