Release Notes for Snare Central v8.1.0

Snare Central v8.1.0 was released on 17th December, 2019.

Snare Central incorporates the Agent Management Console (AMC), the v2.3.2 Reflector, the v1.3.2 Snare Agent Manager (SAM), and the v5.3.1 Snare Enterprise Agent for Linux.

If the threat intelligence component is active, version 6.7.2 of ElasticSearch is installed.

Change Log

Overview

Snare Central version 8.1.0 introduces new user experience for login and site navigation, as well as a number of enhancements and bug fixes. This is the first phase in our journey towards updating the User Interface and enhancing the user experience of the Snare Central. For access to the new User Guide please refer to the following guide.

User Interface updates 

  • Log in screen

    v8.0.0v8.1.0

  • Side and Top navigation

    • Top level menu items (Reports, Agent Management, Status and System) were moved to the collapsible left-hand-side menu, along with their sub-menus
    • Context actions (Configure, Access Control, Schedule, Queue/Query, Refresh/Regenerate, Attachment) as well as Log out are now at the right-hand-side of the top bar

      v8.0.0v8.1.0

  • Reports navigation
    • Selecting Reports from the menu opens reports navigation page

    • Navigate reports tree by clicking on a container (folder icon) or bread crumbs
    • Drag and Drop reports and containers
    • Free-text search of reports
    • Alphabetical sorting of the reports
    • Click on ellipsis ("...") to see report-related actions (Clone, Rename, Delete) or container-related actions (Rename, Export Objectives, Delete All)
    • Click on a report to open a report page
    • Add New Container and Add New Objective buttons are on top

      v8.0.0v8.1.0

  • Agent Management > Snare Agents > Remote Management
    • The layout of the page has been modified to display a list of Agent Management objectives. 

    • By default there is one generic Manage Agents objective.
    • Click on ellipsis ("...") to see available actions (Clone, Rename, Delete)
    • Click on an objective to open it and see the agents and their configurations. 
    • Search and sorting of the objectives is supported. 

      v8.0.0v8.1.0

  • Health Checker Alert
    • Appears at the bottom of the left hand side menu
    • The heart icon changes colour depending on Health Checker status (green, orange or red for ok, warning or error)

      v8.0.0v8.1.0

Features and Enhancements

  • Improved RAM consumption of large queries. The SnareStore query backend is now enabled by default, providing a boost in query speed for most existing queries - particularly those objectives that are regenerated on a regular basis
  • Added Health Checker checks for Elastic health and operation (Status > Snare Health Checker > ElasticSearch Status Check , ElasticSearch Log Check)
  • Added ability to start and stop ElasticSearch from the Snare Central UI without disabling Threat Intelligence (System > Administrative Tools > Snare Threat Intelligence > Start/Restart/Stop ElasticSearch without TI)
  • When enabled, for systems with 8Gb of RAM or more, the ElasticSearch heap size has been upgraded to 4Gb
  • Performance enhancements for the Collector/Reflector subsystem
  • Updated Documentation link to point to the User Guide on public Confluence

Bug Fixes

  • Restored graphs that were missing from System Status objective
  • Various minor bug fixes

User Guide

The following is an offline version of the User Guide related to this release.

For an up-to-date version refer to the online version here.

Operating System Updates

The following table provides information on those packages that have been updated since the release of Snare Server 8.0.

PackageSnare Server 8.0Snare Server 8.1Package Description
php7.2-opcache7.2.19-0ubuntu0.18.04.27.2.24-0ubuntu0.18.04.1Zend OpCache module for PHP
php7.2-readline7.2.19-0ubuntu0.18.04.27.2.24-0ubuntu0.18.04.1readline module for PHP
libirs160:amd641:9.11.3+dfsg-1ubuntu1.91:9.11.3+dfsg-1ubuntu1.10DNS Shared Library used by BIND
dnsutils1:9.11.3+dfsg-1ubuntu1.91:9.11.3+dfsg-1ubuntu1.10Clients provided with BIND
systemd-sysv237-3ubuntu10.29237-3ubuntu10.31system and service manager - SysV links
linux-headers-4.15.0-70-generic
4.15.0-70.79Linux kernel headers for version 4.15.0 on 64 bit x86 SMP
php7.2-cli7.2.19-0ubuntu0.18.04.27.2.24-0ubuntu0.18.04.1command-line interpreter for the PHP scripting language
samba-libs:amd642:4.7.6+dfsg~ubuntu-0ubuntu2.112:4.7.6+dfsg~ubuntu-0ubuntu2.13Samba core libraries
python3-gdbm:amd643.6.8-1~18.043.6.9-1~18.04GNU dbm database support for Python 3.x
samba-common2:4.7.6+dfsg~ubuntu-0ubuntu2.112:4.7.6+dfsg~ubuntu-0ubuntu2.13common files used by both the Samba server and client
debian-installer20101020ubuntu543.1020101020ubuntu543.11Debian Installer documentation
initramfs-tools-bin0.130ubuntu3.80.130ubuntu3.9binaries used by initramfs-tools
libwbclient0:amd642:4.7.6+dfsg~ubuntu-0ubuntu2.112:4.7.6+dfsg~ubuntu-0ubuntu2.13Samba winbind client library
libidn2-0:amd642.0.4-1.1build22.0.4-1.1ubuntu0.2Internationalized domain names (IDNA2008/TR46) library
python2.72.7.15-4ubuntu4~18.04.12.7.15-4ubuntu4~18.04.2Interactive high-level object-oriented language (version 2.7)
libapache2-mod-php7.27.2.19-0ubuntu0.18.04.27.2.24-0ubuntu0.18.04.1server-side, HTML-embedded scripting language (Apache 2 module)
libpython3.6:amd643.6.8-1~18.04.23.6.8-1~18.04.3Shared Python runtime library (version 3.6)
bind9-host1:9.11.3+dfsg-1ubuntu1.91:9.11.3+dfsg-1ubuntu1.10DNS lookup utility (deprecated)
samba-vfs-modules2:4.7.6+dfsg~ubuntu-0ubuntu2.112:4.7.6+dfsg~ubuntu-0ubuntu2.13Samba Virtual FileSystem plugins
liblwres160:amd641:9.11.3+dfsg-1ubuntu1.91:9.11.3+dfsg-1ubuntu1.10Lightweight Resolver Library used by BIND
libibverbs1:amd6417.1-1ubuntu0.117.1-1ubuntu0.2Library for direct userspace use of RDMA (InfiniBand/iWARP)
nplan0.97-0ubuntu1~18.04.10.98-0ubuntu1~18.04.1YAML network configuration abstraction - transitional package
libnss-systemd:amd64237-3ubuntu10.29237-3ubuntu10.31nss module providing dynamic user and group name resolution
python-samba2:4.7.6+dfsg~ubuntu-0ubuntu2.112:4.7.6+dfsg~ubuntu-0ubuntu2.13Python bindings for Samba
samba2:4.7.6+dfsg~ubuntu-0ubuntu2.112:4.7.6+dfsg~ubuntu-0ubuntu2.13SMB/CIFS file, print, and login server for Unix
linux-firmware1.173.91.173.12Firmware for Linux kernel drivers
unattended-upgrades1.1ubuntu1.18.04.111.1ubuntu1.18.04.12automatic installation of security upgrades
libisc169:amd641:9.11.3+dfsg-1ubuntu1.91:9.11.3+dfsg-1ubuntu1.10ISC Shared Library used by BIND
librados212.2.12-0ubuntu0.18.04.212.2.12-0ubuntu0.18.04.3RADOS distributed object store client library
python2.7-minimal2.7.15-4ubuntu4~18.04.12.7.15-4ubuntu4~18.04.2Minimal subset of the Python language (version 2.7)
sudo1.8.21p2-3ubuntu11.8.21p2-3ubuntu1.1Provide limited super user privileges to specific users
libcom-err2:amd641.44.1-1ubuntu1.11.44.1-1ubuntu1.2common error description library
php7.2-json7.2.19-0ubuntu0.18.04.27.2.24-0ubuntu0.18.04.1JSON module for PHP
udev237-3ubuntu10.29237-3ubuntu10.31/dev/ and hotplug management daemon
libudev1:amd64237-3ubuntu10.29237-3ubuntu10.31libudev shared library
distro-info-data0.37ubuntu0.50.37ubuntu0.6information about the distributions' releases (data files)
libxslt1.1:amd641.1.29-5ubuntu0.11.1.29-5ubuntu0.2XSLT 1.0 processing library - runtime library
libcephfs212.2.12-0ubuntu0.18.04.212.2.12-0ubuntu0.18.04.3Ceph distributed file system client library
php7.27.2.19-0ubuntu0.18.04.27.2.24-0ubuntu0.18.04.1server-side, HTML-embedded scripting language (metapackage)
php7.2-sqlite37.2.19-0ubuntu0.18.04.27.2.24-0ubuntu0.18.04.1SQLite3 module for PHP
python3.6-minimal3.6.8-1~18.04.23.6.8-1~18.04.3Minimal subset of the Python language (version 3.6)
dpkg1.19.0.5ubuntu2.21.19.0.5ubuntu2.3Debian package management system
libpython2.7-stdlib:amd642.7.15-4ubuntu4~18.04.12.7.15-4ubuntu4~18.04.2Interactive high-level object-oriented language (standard library, version 2.7)
ibverbs-providers:amd6417.1-1ubuntu0.117.1-1ubuntu0.2User space provider drivers for libibverbs
netplan.io0.97-0ubuntu1~18.04.10.98-0ubuntu1~18.04.1YAML network configuration abstraction for various backends
linux-image-4.15.0-70-generic
4.15.0-70.79Signed kernel image generic
linux-modules-extra-4.15.0-70-generic 4.15.0-70.79
4.15.0-70.79
linux-headers-4.15.0-70
4.15.0-70.79Header files related to Linux kernel version 4.15.0
intel-microcode3.20190618.0ubuntu0.18.04.13.20191112-0ubuntu0.18.04.2Processor microcode firmware for Intel CPUs
libss2:amd641.44.1-1ubuntu1.11.44.1-1ubuntu1.2command-line interface parsing library
python3-problem-report2.20.9-0ubuntu7.72.20.9-0ubuntu7.9Python 3 library to handle problem reports
libbind9-160:amd641:9.11.3+dfsg-1ubuntu1.91:9.11.3+dfsg-1ubuntu1.10BIND9 Shared Library used by BIND
apport2.20.9-0ubuntu7.72.20.9-0ubuntu7.9automatically generate crash reports for debugging
xsltproc1.1.29-5ubuntu0.11.1.29-5ubuntu0.2XSLT 1.0 command line processor
libisc-export169:amd641:9.11.3+dfsg-1ubuntu1.91:9.11.3+dfsg-1ubuntu1.10Exported ISC Shared Library
e2fsprogs1.44.1-1ubuntu1.11.44.1-1ubuntu1.2ext2/ext3/ext4 file system utilities
libdns-export11001:9.11.3+dfsg-1ubuntu1.91:9.11.3+dfsg-1ubuntu1.10Exported DNS Shared Library
clamav0.100.3+dfsg-0ubuntu0.18.04.10.101.4+dfsg-0ubuntu0.18.04.1anti-virus utility for Unix - command-line interface
php7.2-curl7.2.19-0ubuntu0.18.04.27.2.24-0ubuntu0.18.04.1CURL module for PHP
libtiff5:amd644.0.9-5ubuntu0.24.0.9-5ubuntu0.3Tag Image File Format (TIFF) library
php7.2-gd7.2.19-0ubuntu0.18.04.27.2.24-0ubuntu0.18.04.1GD module for PHP
libext2fs2:amd641.44.1-1ubuntu1.11.44.1-1ubuntu1.2ext2/ext3/ext4 file system libraries
libpam-systemd:amd64237-3ubuntu10.29237-3ubuntu10.31system and service manager - PAM module
php7.2-xml7.2.19-0ubuntu0.18.04.27.2.24-0ubuntu0.18.04.1DOM, SimpleXML, WDDX, XML, and XSL module for PHP
clamav-base0.100.3+dfsg-0ubuntu0.18.04.10.101.4+dfsg-0ubuntu0.18.04.1anti-virus utility for Unix - base package
libsystemd0:amd64237-3ubuntu10.29237-3ubuntu10.31systemd utility library
thermald1.7.0-5ubuntu21.7.0-5ubuntu5Thermal monitoring and controlling daemon
libmagic-mgc1:5.32-2ubuntu0.21:5.32-2ubuntu0.3File type determination library using "magic" numbers (compiled magic file)
grep3.1-23.1-2build1GNU grep, egrep and fgrep
linux-image-generic4.15.0.64.664.15.0.70.72Generic Linux kernel image
libisccfg160:amd641:9.11.3+dfsg-1ubuntu1.91:9.11.3+dfsg-1ubuntu1.10Config File Handling Library used by BIND
libjpeg-turbo8:amd641.5.2-0ubuntu5.18.04.11.5.2-0ubuntu5.18.04.3IJG JPEG compliant runtime library.
libpython3.6-minimal:amd643.6.8-1~18.04.23.6.8-1~18.04.3Minimal subset of the Python language (version 3.6)
file1:5.32-2ubuntu0.21:5.32-2ubuntu0.3Recognize the type of data in a file using "magic" numbers
libclamav9:amd64libclamav7 0.100.3+dfsg-0ubuntu0.18.04.10.101.4+dfsg-0ubuntu0.18.04.1anti-virus utility for Unix - library
tzdata2019b-0ubuntu0.18.042019c-0ubuntu0.18.04time zone and daylight-saving time data
libmagic1:amd641:5.32-2ubuntu0.21:5.32-2ubuntu0.3Recognize the type of data in a file using "magic" numbers - library
libpython2.7:amd642.7.15-4ubuntu4~18.04.12.7.15-4ubuntu4~18.04.2Shared Python runtime library (version 2.7)
libdns1100:amd641:9.11.3+dfsg-1ubuntu1.91:9.11.3+dfsg-1ubuntu1.10DNS Shared Library used by BIND
initramfs-tools0.130ubuntu3.80.130ubuntu3.9generic modular initramfs generator (automation)
linux-headers-generic4.15.0.64.664.15.0.70.72Generic Linux kernel headers
libpython3.6-stdlib:amd643.6.8-1~18.04.23.6.8-1~18.04.3Interactive high-level object-oriented language (standard library, version 3.6)
cpio2.12+dfsg-62.12+dfsg-6ubuntu0.18.04.1GNU cpio -- a program to manage archives of files
samba-common-bin2:4.7.6+dfsg~ubuntu-0ubuntu2.112:4.7.6+dfsg~ubuntu-0ubuntu2.13Samba common files used by both the server and the client
initramfs-tools-core0.130ubuntu3.80.130ubuntu3.9generic modular initramfs generator (core tools)
python3.63.6.8-1~18.04.23.6.8-1~18.04.3Interactive high-level object-oriented language (version 3.6)
samba-dsdb-modules2:4.7.6+dfsg~ubuntu-0ubuntu2.112:4.7.6+dfsg~ubuntu-0ubuntu2.13Samba Directory Services Database
php7.2-phpdbg7.2.19-0ubuntu0.18.04.27.2.24-0ubuntu0.18.04.1server-side, HTML-embedded scripting language (PHPDBG binary)
linux-modules-4.15.0-70-generic
4.15.0-70.79Linux kernel extra modules for version 4.15.0 on 64 bit x86 SMP
libpython2.7-minimal:amd642.7.15-4ubuntu4~18.04.12.7.15-4ubuntu4~18.04.2Minimal subset of the Python language (version 2.7)
systemd237-3ubuntu10.29237-3ubuntu10.31system and service manager
python3-apport2.20.9-0ubuntu7.72.20.9-0ubuntu7.9Python 3 library for Apport crash report handling
php7.2-common7.2.19-0ubuntu0.18.04.27.2.24-0ubuntu0.18.04.1documentation, examples and common module for PHP
base-files10.1ubuntu2.610.1ubuntu2.7Debian base system miscellaneous files
clamav-freshclam0.100.3+dfsg-0ubuntu0.18.04.10.101.4+dfsg-0ubuntu0.18.04.1anti-virus utility for Unix - virus database update utility
php7.2-ldap7.2.19-0ubuntu0.18.04.27.2.24-0ubuntu0.18.04.1LDAP module for PHP
libisccc160:amd641:9.11.3+dfsg-1ubuntu1.91:9.11.3+dfsg-1ubuntu1.10Command Channel Library used by BIND