The purpose of this section is to discuss the parameter settings of the configuration file. The Snare configuration file is located at /etc/security/snare.conf, and this location may not be changed. If the configuration file does not exist, the audit daemon will not actively audit events until a correctly formatted configuration file is present.
...
The format of the audit configuration file is discussed below.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
|
|
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
|
|
|
|
|
|
|
|
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
|
|
|
|
|
|
|
|
|
|
| |
|
|
|
|
| |
|
|
|
|
|
|
|
| |
|
|
|
|
|
|
|
|
|
|
SAM1AuthKey
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
| |
|
|
|
|
|
|
|
|
|
|
| |
|
|
Objective# (where |
# |
is |
a |
serial |
no. |
starting |
with |
1) |
|
[Filter] |
|
|
Filter# |
(where |
# |
is |
a |
serial |
number) |
|
|
|
|
|
|
|
|
|
|
|
|
|
For |
example: "Filter1": |
"criticality=0,5,5,5,0,1,0,0,0,0match=\"*\"regex=0state=1uuid=7e90d723-219c-46a6-943e-55573532e05f" |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
|
|
Log# |
(where |
# |
is |
a |
serial |
number) | This |
section |
describes |
the |
format |
of |
the |
log |
file |
monitors. |
example: "Log1": |
"logtype=0logval=\"\"linetype=1lineval=\"1\"watchtype=0watchval=\"1\"dirfilter=\"\/var\/log\"filefilter=\"syslog\"features=0state=1uuid=8b5678d1-abc2-467c-af05-5318b9d1c94d" |
- |
an |
integer |
representing |
the |
type |
of |
logs |
being |
collected: |
0 |
- |
Generic |
log |
format(default); |
1 |
- |
Apache |
web |
logs; |
2 |
- |
Exchange |
message |
tracking |
logs |
pre |
2007; |
3 |
- |
Exchange |
message |
tracking |
logs |
2007; |
4 |
- |
Exchange |
message |
tracking |
logs |
2010/2013; |
5 |
- |
Microsoft |
IIS |
web |
server |
logs; |
6 |
- |
Microsoft |
ISA |
firewall |
logs; |
7 |
- |
Microsoft |
ISA |
web |
logs; |
8 |
- |
Microsoft |
proxy |
server |
logs; |
9 |
- |
Microsoft |
SMTP |
logs; |
10 |
- |
Squid |
proxy |
logs; |
11 |
- |
VMS |
Security |
Logs; |
12 |
- |
Custom |
Event |
log; |
13 |
- |
Microsoft |
DNS |
server |
logs; |
14 |
- |
NCR |
ATM |
Journal |
Logs; |
15 |
- |
DHCP |
Logs logval |
- |
user-defined |
string |
that |
will |
be |
used |
as |
a |
log |
type |
in |
the |
event |
header |
if |
the |
logtype |
= |
12 |
- |
Custom |
Event |
Log. linetype |
- |
an |
integer |
defining |
what |
comprises |
a |
single |
event: |
0 |
- |
Single |
Line |
(every |
line |
in |
the |
monitored |
file |
is |
converted |
to |
a |
separate |
event); |
1 |
- |
Fixed |
Number |
of |
Lines; |
2 |
- |
Line |
separating |
events |
(a |
line |
specified |
in |
lineval |
acts |
as |
event |
separator) lineval |
- |
if |
linetype |
= |
1, |
a |
string |
representing |
the |
number |
of |
lines |
to |
be |
read |
as |
one |
event; |
if |
linetype |
= |
2, |
this |
is |
the |
line |
that |
separates |
events, |
for |
example, |
"<end>". |
watchtype |
- |
an |
integer |
indicating |
which |
files |
should |
be |
monitored |
in |
the |
given |
directory: |
0 |
- |
All |
matching |
files; |
1 |
- |
Last |
matching |
file |
(alphabetically); |
2 |
- |
First |
matching |
file |
(alphabetically); |
3 |
- |
Fixed |
number |
of |
first |
matching |
files; |
4 |
- |
Fixed |
number |
of |
last |
matching |
files watchval |
- |
if |
watchtype |
= |
3 |
or |
4, |
a |
string |
representing |
the |
number |
of |
first/last |
matching |
files, |
otherwise |
"1" dirfilter |
- |
a |
string |
representing |
fully |
qualified |
path |
to |
the |
desired |
log |
file |
or |
the |
directory |
containing |
the |
target |
log |
files filefilter |
- |
a |
string |
representing |
the |
file |
name |
or |
file |
name |
pattern |
to |
monitor |
for |
new |
logs features |
- |
an |
integer |
representing |
a |
bitmap |
of |
extra |
features, |
such |
as |
comments |
inclusion, |
date-based |
or |
regex-based |
file |
matching, |
etc. |
This |
value |
is |
set |
programmatically |
based |
on |
other |
selections. state |
- |
an |
integer |
representing |
the |
state |
of |
Log |
file |
monitor |
configuration. |
Disabled |
= |
0, |
Enabled |
= |
1, |
Requiring |
Service |
Restart |
= |
2. uuid |
- |
a |
unique |
16-byte |
identifier |
of |
this |
Log |
file |
monitor. |
Log |
Configuration |
page |
in |
this |
User |
Guide |
for |
more |
details. | |
|
|
FIM#
|
|
|
|
License# (where |
# |
is |
a |
serial |
no. |
starting |
with |
1) |
"License1": |
"Product-Name=...", | |