Release Notes for Snare Epilog Agent v5.5.1

Snare Epilog Agent v5.5.1 was released on 28th September 2021.

(Note: May be purchased separately or as a combined Windows/Epilog agent)

Security Updates

  • OpenSSL upgraded to version 1.1.1l 

Bug Fixes

  • Fixed the issue where Snare Agent was showing 'cache is full' warning even when network destination is not down and not very slow. Due to this issue, the overall EPS of the Snare starts dropping and in some cases EPS becomes 0.
    Snare Agent might still show this message for very slow network destination or when there is network congestion.

  • Heartbeat events sent in Syslog JSON format now have criticality (severity) in the syslog header
  • Syslog 5424 headers of events sent in Syslog (RFC 5424) and Syslog JSON formats no longer contain erroneous tab character in MSGID field
  • Fixed inconsistent Auth Keys' length validation, allowing TLS Auth Key and SAM Auth Key length to be within [8, 4096] range
  • Removed erroneous error message when the destination is configured with a combination of Snare v2 format and TLS_AUTH protocol
  • Updated Knowledge Base link that was broken
  • Fixed the issue where cache loading for audit log events was causing the loading of incomplete events