Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.



Tip

Snare Windows Agent v5.8.1 was released on xx 19th June , 2024.


Warning

Since v5.8.0, upgrading Snare Agent from versions earlier than 5.4.0 for Agents that had password enabled is not supported.

Customers who need to upgrade the Agent from pre-5.4.0 version, are advised to perform a two-step upgrade:

  • Step 1 - Upgrade from pre-5.4.0 version to v5.7.0 or 5.7.1
  • Step 2 - Upgrade from v5.7.* to the latest version

Security Updates

  • 3rd party libraries upgraded: 
    • OpenSSL upgraded to version 3.1.SA-43295

New Features and Enhancements

  • Allow Agent service to start up and display Web UI with the relevant error message when the Agent is running with permissions insufficient for audit logs collection SA-4228SA-4229collection
  • Removed registry values that are no longer in use from the 'Remote' registry keySA-4326
  • Preventative code maintenance SA-3564maintenance

Bug Fixes

  • Fixed handling of remotely-configured SNARE V2 and JSON formats. These formats are now properly applied to outgoing events after configuration update is obtained from SAMSA-4334 Related to Support Case SSUP-1007 / SSD-1718
  • Fixed scenario where log audit, FIM and RIM policies could not be completely removed via remote configuration managed by SAMSA-4339 Related to Support Case SSUP-1018 / SSD-1773
  • Fixed a crash that could occur when sending a Microsoft windows CAPI2 event in Snare v2 or JSON formats
  • Fixed handling of duplicated data fields in Windows events sent in Snare v2 or JSON formats
  • Fix for issue where invalid event data could result in Agent being stuck attempting to process such eventSA-4087.
  • Improved validation of 'Event ID Match' input in Audit PolicySA-4214 Related to Support Case SSUP-885 / SSD-1281
  • Removed misleading erroneous Error logged after reading last Advanced Audit policy SA-4279 Related to Support Case SSUP-951 / SSD-1449policy
  • Fixed license file names listed on the 'Select a License' page of the installer. If the file name contained parentheses, only the text in parentheses was displayedSA-4283
  • Fixed spelling mistakes in labels on the Advanced Audit and FAM policy configuration pagesSA-4244SA-4298

User Guide

The following is an offline version of the User Guide related to this release.

...