Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Events collected by the agent that meet the filtering requirements as per the audit configuration, will be displayed in the Latest Events window.  This display is NOT a display from the event log file, but rather a temporary display from a shared memory connection between the web UI and the the Snare service.  This list will be empty if the agent has not yet found any matching events or if there has been a network problem and the agent has temporarily suspended event processing.

Image RemovedImage Added
 

A key feature of Snare service is that events are not stored locally on the host, but rather sent out over the network to one or more remote hosts, and a summary version of the events is displayed on the window.

...

Below is an example of the latest FIM events:

...

Image Added


Below is an example of the latest Log Auditing events:

Image RemovedImage Added

Other useful information of the Latest Events Window is as follows:

  • restricted to a list of 20 entries and cannot be cleared, except by restarting the Snare service
  • new events will be displayed with an alarm bell icon next to it
  • events are highlighted in the criticality level colour nominated in your audit policies
  • the window will automatically refresh every 30 15 seconds for event logs or when the Latest Events menu item is selected
  • displays the status of the current network connection(s) to the log server
  • displays the date and time of the last HeartBeat sent, if applicable

...