Snare Windows Agent v5.3.1 was released on XX August 2019.
Bug Fixes
- Resolved an issue in the destination handling when a TCP destination was incorrectly treated as TLS destination. Due to this issue the Snare service can stop and require restart. This issue is fixed in this release and now Snare handles the mismatch of destination properly.
- There was issue in Snare that when it's running with a license that is close to expiry date it can go into deadlock state while sending license expiry heart beat. Due to this issue, Snare stops sending new logs. This issue fixed in this release and now license expiry heart beats are properly handled.
- Updated Windows events matching against Exclude objectives: if the event is not matching the exclude filter, the agent will move on to the next objective to look for a match, rather than including the event. This bug made it impossible to have multiple exclude objectives with different criteria.
- Fixed an issue whereby Log Filters were not filtering correctly when more than 1 filter was configured and included an "Exclude" filter.
- Resolved an issue that caused SAM Centralized Agent Upgrades feature to fail when upgrading from release v5.3.0.