Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  1. Follow steps outlined here to install the Snare agent. Agent Installation - Snare Windows Agent v5 Documentation - Confluence

  2. To collect the DNS logs from the newly created log file navigate to “Log Sources > Log Files”

  3. Click “Add”, Select the log type and select “ Microsoft DNS server logs”

  4. Select “Line seperating events” and in put “\r\n\r\n” this helps the agent identify where the individual logs start and end in the txt file.

  5. Paste in the location of the log file e.g. C:\DNS.txt into the “Log file or Directory Field”

  6. In the “Log File Format” Field input the name of the file e.g. *.log

    image-20250218-102709.png
  7. Once happy click Change configuration and restart the service to save the change.

  8. Once happy and changes applieed select “Destination configuration”.

    image-20241203-093353.png
  9. Under the “Network Destinations” section, enter the domain/IP address and port for Snare Reflector, and ensure Format is “Snare” and “Delimiter Character” is “Tab”.

...