This page enables you to configure network and file destinations. The ability to configure general settings will apply to all destinations of any type.

Besides, it enables configuring additional data to be included in each event log generated by the agent

Network Destinations

Multiple destinations per protocol may be configured to send the events to your SIEM by setting the following parameters:

Network Destinations must be created one at time. To add another row to enable the creation of additional Network Destinations simply click the Update Destinations button to confirm the addition of the new Network Destination. Upon the creation of the new Network Destination a new empty row will be made available.

Network Destinations can be removed by clearing the Domain / IP field and clicking Update Destinations.

File Destinations

Multiple File Destinations can be setup utilizing various formats can be setup to help you log information locally or on a drive that is network shared.

File Destinations must be created one at time. To add another row to enable the creation of additional File Destinations simply click the Update Destinations button to confirm the addition of the new File Destination. Upon the creation of the new File Destination a new empty row will be made available.

File Destinations can be removed by clearing the Path & Filename field and clicking Update Destinations.


The purpose of the file destination is to store the copy of each event that is successfully sent to at least one network destination. If there is no network destination and at least one file destination, Snare will keep writing new events to the file destination but will not show these events in Latest Events page. If there are more than one network destinations and one file destination, Snare will write a event to the file destination if it can first successfully send event to at least one of the network destinations. If none of the network destinations is available, Snare will add events to a memory cache and will write those events to the file destination as well. Once the memory cache reaches its capacity, no additional events will be written to the file destination. If there is a need to store the events locally only in a file destination then a dummy UDP network destination must be added.


Hostname Options

The settings apply to the settings to modify the hostname associated with the processed event log. 

General Destination Options

The settings apply to all network and file destinations.

Event Options

These settings allow you to configure additional data to be included in each event log generated by the agent.

If Event Source ID is configured, the ID is displayed on the home screen (Audit Service Status) of the Agent UI and every event log from the agent in SNARE format or one of the SYSLOG formats will have EventSourceId=<value> appended at the end of the message.


To save and set the changes to the above settings, and to ensure the audit daemon has received the new configuration perform the following:

  1. Click on Update Destinations to save any changes to the registry.
  2. Click on the Apply Configuration & Restart Service menu item.