...
Collects logs on UDP/TCP port 514 for syslog devices like firewalls, routers switches, other syslog appliances. It can also use tls on tcp port 6514
Snare Agents logs are received on UDP/TCP 6161
Snare Agents encrypted logs from TLS agents on TCP 6163 and 6164 using TLS_AUTH
NTP is on UDP 123 for network time
SSH network access is on TCP port 22 for the CLI access
Web interface uses TCP port 80/443
SNMP-traps UDP port 162
FTP on TCP port 20/21 - if enabled
NetBIOS UDP/138/139 TCP 139/445– if enabled
If using OpenVAS then port HTTPS over TCP 9392 is used in V8 Snare Central
...