Release Notes for Snare Central v8.1.0
Snare Central v8.1.0 was released on 17th December, 2019.
Snare Central incorporates the Agent Management Console (AMC), the v2.3.2 Reflector, the v1.3.2 Snare Agent Manager (SAM), and the v5.3.1 Snare Enterprise Agent for Linux.
If the threat intelligence component is active, version 6.7.2 of ElasticSearch is installed.
Change Log
Overview
Snare Central version 8.1.0 introduces new user experience for login and site navigation, as well as a number of enhancements and bug fixes. This is the first phase in our journey towards updating the User Interface and enhancing the user experience of the Snare Central. For access to the new User Guide please refer to the following guide.
User Interface updates
Log in screen
v8.0.0 v8.1.0 Side and Top navigation
- Top level menu items (Reports, Agent Management, Status and System) were moved to the collapsible left-hand-side menu, along with their sub-menus
Context actions (Configure, Access Control, Schedule, Queue/Query, Refresh/Regenerate, Attachment) as well as Log out are now at the right-hand-side of the top bar
v8.0.0 v8.1.0
- Reports navigation
Selecting Reports from the menu opens reports navigation page
- Navigate reports tree by clicking on a container (folder icon) or bread crumbs
- Drag and Drop reports and containers
- Free-text search of reports
- Alphabetical sorting of the reports
- Click on ellipsis ("...") to see report-related actions (Clone, Rename, Delete) or container-related actions (Rename, Export Objectives, Delete All)
- Click on a report to open a report page
Add New Container and Add New Objective buttons are on top
v8.0.0 v8.1.0
- Agent Management > Snare Agents > Remote Management
The layout of the page has been modified to display a list of Agent Management objectives.
- By default there is one generic Manage Agents objective.
- Click on ellipsis ("...") to see available actions (Clone, Rename, Delete)
- Click on an objective to open it and see the agents and their configurations.
Search and sorting of the objectives is supported.
v8.0.0 v8.1.0
- Health Checker Alert
- Appears at the bottom of the left hand side menu
The heart icon changes colour depending on Health Checker status (green, orange or red for ok, warning or error)
v8.0.0 v8.1.0
Features and Enhancements
- Improved RAM consumption of large queries. The SnareStore query backend is now enabled by default, providing a boost in query speed for most existing queries - particularly those objectives that are regenerated on a regular basis
- Added Health Checker checks for Elastic health and operation (Status > Snare Health Checker > ElasticSearch Status Check , ElasticSearch Log Check)
- Added ability to start and stop ElasticSearch from the Snare Central UI without disabling Threat Intelligence (System > Administrative Tools > Snare Threat Intelligence > Start/Restart/Stop ElasticSearch without TI)
- When enabled, for systems with 8Gb of RAM or more, the ElasticSearch heap size has been upgraded to 4Gb
- Performance enhancements for the Collector/Reflector subsystem
- Updated Documentation link to point to the User Guide on public Confluence
Bug Fixes
- Restored graphs that were missing from System Status objective
- Various minor bug fixes
User Guide
The following is an offline version of the User Guide related to this release.
For an up-to-date version refer to the online version here.
Operating System Updates
The following table provides information on those packages that have been updated since the release of Snare Server 8.0.
Package | Snare Server 8.0 | Snare Server 8.1 | Package Description |
---|---|---|---|
php7.2-opcache | 7.2.19-0ubuntu0.18.04.2 | 7.2.24-0ubuntu0.18.04.1 | Zend OpCache module for PHP |
php7.2-readline | 7.2.19-0ubuntu0.18.04.2 | 7.2.24-0ubuntu0.18.04.1 | readline module for PHP |
libirs160:amd64 | 1:9.11.3+dfsg-1ubuntu1.9 | 1:9.11.3+dfsg-1ubuntu1.10 | DNS Shared Library used by BIND |
dnsutils | 1:9.11.3+dfsg-1ubuntu1.9 | 1:9.11.3+dfsg-1ubuntu1.10 | Clients provided with BIND |
systemd-sysv | 237-3ubuntu10.29 | 237-3ubuntu10.31 | system and service manager - SysV links |
linux-headers-4.15.0-70-generic | 4.15.0-70.79 | Linux kernel headers for version 4.15.0 on 64 bit x86 SMP | |
php7.2-cli | 7.2.19-0ubuntu0.18.04.2 | 7.2.24-0ubuntu0.18.04.1 | command-line interpreter for the PHP scripting language |
samba-libs:amd64 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.11 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.13 | Samba core libraries |
python3-gdbm:amd64 | 3.6.8-1~18.04 | 3.6.9-1~18.04 | GNU dbm database support for Python 3.x |
samba-common | 2:4.7.6+dfsg~ubuntu-0ubuntu2.11 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.13 | common files used by both the Samba server and client |
debian-installer | 20101020ubuntu543.10 | 20101020ubuntu543.11 | Debian Installer documentation |
initramfs-tools-bin | 0.130ubuntu3.8 | 0.130ubuntu3.9 | binaries used by initramfs-tools |
libwbclient0:amd64 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.11 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.13 | Samba winbind client library |
libidn2-0:amd64 | 2.0.4-1.1build2 | 2.0.4-1.1ubuntu0.2 | Internationalized domain names (IDNA2008/TR46) library |
python2.7 | 2.7.15-4ubuntu4~18.04.1 | 2.7.15-4ubuntu4~18.04.2 | Interactive high-level object-oriented language (version 2.7) |
libapache2-mod-php7.2 | 7.2.19-0ubuntu0.18.04.2 | 7.2.24-0ubuntu0.18.04.1 | server-side, HTML-embedded scripting language (Apache 2 module) |
libpython3.6:amd64 | 3.6.8-1~18.04.2 | 3.6.8-1~18.04.3 | Shared Python runtime library (version 3.6) |
bind9-host | 1:9.11.3+dfsg-1ubuntu1.9 | 1:9.11.3+dfsg-1ubuntu1.10 | DNS lookup utility (deprecated) |
samba-vfs-modules | 2:4.7.6+dfsg~ubuntu-0ubuntu2.11 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.13 | Samba Virtual FileSystem plugins |
liblwres160:amd64 | 1:9.11.3+dfsg-1ubuntu1.9 | 1:9.11.3+dfsg-1ubuntu1.10 | Lightweight Resolver Library used by BIND |
libibverbs1:amd64 | 17.1-1ubuntu0.1 | 17.1-1ubuntu0.2 | Library for direct userspace use of RDMA (InfiniBand/iWARP) |
nplan | 0.97-0ubuntu1~18.04.1 | 0.98-0ubuntu1~18.04.1 | YAML network configuration abstraction - transitional package |
libnss-systemd:amd64 | 237-3ubuntu10.29 | 237-3ubuntu10.31 | nss module providing dynamic user and group name resolution |
python-samba | 2:4.7.6+dfsg~ubuntu-0ubuntu2.11 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.13 | Python bindings for Samba |
samba | 2:4.7.6+dfsg~ubuntu-0ubuntu2.11 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.13 | SMB/CIFS file, print, and login server for Unix |
linux-firmware | 1.173.9 | 1.173.12 | Firmware for Linux kernel drivers |
unattended-upgrades | 1.1ubuntu1.18.04.11 | 1.1ubuntu1.18.04.12 | automatic installation of security upgrades |
libisc169:amd64 | 1:9.11.3+dfsg-1ubuntu1.9 | 1:9.11.3+dfsg-1ubuntu1.10 | ISC Shared Library used by BIND |
librados2 | 12.2.12-0ubuntu0.18.04.2 | 12.2.12-0ubuntu0.18.04.3 | RADOS distributed object store client library |
python2.7-minimal | 2.7.15-4ubuntu4~18.04.1 | 2.7.15-4ubuntu4~18.04.2 | Minimal subset of the Python language (version 2.7) |
sudo | 1.8.21p2-3ubuntu1 | 1.8.21p2-3ubuntu1.1 | Provide limited super user privileges to specific users |
libcom-err2:amd64 | 1.44.1-1ubuntu1.1 | 1.44.1-1ubuntu1.2 | common error description library |
php7.2-json | 7.2.19-0ubuntu0.18.04.2 | 7.2.24-0ubuntu0.18.04.1 | JSON module for PHP |
udev | 237-3ubuntu10.29 | 237-3ubuntu10.31 | /dev/ and hotplug management daemon |
libudev1:amd64 | 237-3ubuntu10.29 | 237-3ubuntu10.31 | libudev shared library |
distro-info-data | 0.37ubuntu0.5 | 0.37ubuntu0.6 | information about the distributions' releases (data files) |
libxslt1.1:amd64 | 1.1.29-5ubuntu0.1 | 1.1.29-5ubuntu0.2 | XSLT 1.0 processing library - runtime library |
libcephfs2 | 12.2.12-0ubuntu0.18.04.2 | 12.2.12-0ubuntu0.18.04.3 | Ceph distributed file system client library |
php7.2 | 7.2.19-0ubuntu0.18.04.2 | 7.2.24-0ubuntu0.18.04.1 | server-side, HTML-embedded scripting language (metapackage) |
php7.2-sqlite3 | 7.2.19-0ubuntu0.18.04.2 | 7.2.24-0ubuntu0.18.04.1 | SQLite3 module for PHP |
python3.6-minimal | 3.6.8-1~18.04.2 | 3.6.8-1~18.04.3 | Minimal subset of the Python language (version 3.6) |
dpkg | 1.19.0.5ubuntu2.2 | 1.19.0.5ubuntu2.3 | Debian package management system |
libpython2.7-stdlib:amd64 | 2.7.15-4ubuntu4~18.04.1 | 2.7.15-4ubuntu4~18.04.2 | Interactive high-level object-oriented language (standard library, version 2.7) |
ibverbs-providers:amd64 | 17.1-1ubuntu0.1 | 17.1-1ubuntu0.2 | User space provider drivers for libibverbs |
netplan.io | 0.97-0ubuntu1~18.04.1 | 0.98-0ubuntu1~18.04.1 | YAML network configuration abstraction for various backends |
linux-image-4.15.0-70-generic | 4.15.0-70.79 | Signed kernel image generic | |
linux-modules-extra-4.15.0-70-generic 4.15.0-70.79 | 4.15.0-70.79 | ||
linux-headers-4.15.0-70 | 4.15.0-70.79 | Header files related to Linux kernel version 4.15.0 | |
intel-microcode | 3.20190618.0ubuntu0.18.04.1 | 3.20191112-0ubuntu0.18.04.2 | Processor microcode firmware for Intel CPUs |
libss2:amd64 | 1.44.1-1ubuntu1.1 | 1.44.1-1ubuntu1.2 | command-line interface parsing library |
python3-problem-report | 2.20.9-0ubuntu7.7 | 2.20.9-0ubuntu7.9 | Python 3 library to handle problem reports |
libbind9-160:amd64 | 1:9.11.3+dfsg-1ubuntu1.9 | 1:9.11.3+dfsg-1ubuntu1.10 | BIND9 Shared Library used by BIND |
apport | 2.20.9-0ubuntu7.7 | 2.20.9-0ubuntu7.9 | automatically generate crash reports for debugging |
xsltproc | 1.1.29-5ubuntu0.1 | 1.1.29-5ubuntu0.2 | XSLT 1.0 command line processor |
libisc-export169:amd64 | 1:9.11.3+dfsg-1ubuntu1.9 | 1:9.11.3+dfsg-1ubuntu1.10 | Exported ISC Shared Library |
e2fsprogs | 1.44.1-1ubuntu1.1 | 1.44.1-1ubuntu1.2 | ext2/ext3/ext4 file system utilities |
libdns-export1100 | 1:9.11.3+dfsg-1ubuntu1.9 | 1:9.11.3+dfsg-1ubuntu1.10 | Exported DNS Shared Library |
clamav | 0.100.3+dfsg-0ubuntu0.18.04.1 | 0.101.4+dfsg-0ubuntu0.18.04.1 | anti-virus utility for Unix - command-line interface |
php7.2-curl | 7.2.19-0ubuntu0.18.04.2 | 7.2.24-0ubuntu0.18.04.1 | CURL module for PHP |
libtiff5:amd64 | 4.0.9-5ubuntu0.2 | 4.0.9-5ubuntu0.3 | Tag Image File Format (TIFF) library |
php7.2-gd | 7.2.19-0ubuntu0.18.04.2 | 7.2.24-0ubuntu0.18.04.1 | GD module for PHP |
libext2fs2:amd64 | 1.44.1-1ubuntu1.1 | 1.44.1-1ubuntu1.2 | ext2/ext3/ext4 file system libraries |
libpam-systemd:amd64 | 237-3ubuntu10.29 | 237-3ubuntu10.31 | system and service manager - PAM module |
php7.2-xml | 7.2.19-0ubuntu0.18.04.2 | 7.2.24-0ubuntu0.18.04.1 | DOM, SimpleXML, WDDX, XML, and XSL module for PHP |
clamav-base | 0.100.3+dfsg-0ubuntu0.18.04.1 | 0.101.4+dfsg-0ubuntu0.18.04.1 | anti-virus utility for Unix - base package |
libsystemd0:amd64 | 237-3ubuntu10.29 | 237-3ubuntu10.31 | systemd utility library |
thermald | 1.7.0-5ubuntu2 | 1.7.0-5ubuntu5 | Thermal monitoring and controlling daemon |
libmagic-mgc | 1:5.32-2ubuntu0.2 | 1:5.32-2ubuntu0.3 | File type determination library using "magic" numbers (compiled magic file) |
grep | 3.1-2 | 3.1-2build1 | GNU grep, egrep and fgrep |
linux-image-generic | 4.15.0.64.66 | 4.15.0.70.72 | Generic Linux kernel image |
libisccfg160:amd64 | 1:9.11.3+dfsg-1ubuntu1.9 | 1:9.11.3+dfsg-1ubuntu1.10 | Config File Handling Library used by BIND |
libjpeg-turbo8:amd64 | 1.5.2-0ubuntu5.18.04.1 | 1.5.2-0ubuntu5.18.04.3 | IJG JPEG compliant runtime library. |
libpython3.6-minimal:amd64 | 3.6.8-1~18.04.2 | 3.6.8-1~18.04.3 | Minimal subset of the Python language (version 3.6) |
file | 1:5.32-2ubuntu0.2 | 1:5.32-2ubuntu0.3 | Recognize the type of data in a file using "magic" numbers |
libclamav9:amd64 | libclamav7 0.100.3+dfsg-0ubuntu0.18.04.1 | 0.101.4+dfsg-0ubuntu0.18.04.1 | anti-virus utility for Unix - library |
tzdata | 2019b-0ubuntu0.18.04 | 2019c-0ubuntu0.18.04 | time zone and daylight-saving time data |
libmagic1:amd64 | 1:5.32-2ubuntu0.2 | 1:5.32-2ubuntu0.3 | Recognize the type of data in a file using "magic" numbers - library |
libpython2.7:amd64 | 2.7.15-4ubuntu4~18.04.1 | 2.7.15-4ubuntu4~18.04.2 | Shared Python runtime library (version 2.7) |
libdns1100:amd64 | 1:9.11.3+dfsg-1ubuntu1.9 | 1:9.11.3+dfsg-1ubuntu1.10 | DNS Shared Library used by BIND |
initramfs-tools | 0.130ubuntu3.8 | 0.130ubuntu3.9 | generic modular initramfs generator (automation) |
linux-headers-generic | 4.15.0.64.66 | 4.15.0.70.72 | Generic Linux kernel headers |
libpython3.6-stdlib:amd64 | 3.6.8-1~18.04.2 | 3.6.8-1~18.04.3 | Interactive high-level object-oriented language (standard library, version 3.6) |
cpio | 2.12+dfsg-6 | 2.12+dfsg-6ubuntu0.18.04.1 | GNU cpio -- a program to manage archives of files |
samba-common-bin | 2:4.7.6+dfsg~ubuntu-0ubuntu2.11 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.13 | Samba common files used by both the server and the client |
initramfs-tools-core | 0.130ubuntu3.8 | 0.130ubuntu3.9 | generic modular initramfs generator (core tools) |
python3.6 | 3.6.8-1~18.04.2 | 3.6.8-1~18.04.3 | Interactive high-level object-oriented language (version 3.6) |
samba-dsdb-modules | 2:4.7.6+dfsg~ubuntu-0ubuntu2.11 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.13 | Samba Directory Services Database |
php7.2-phpdbg | 7.2.19-0ubuntu0.18.04.2 | 7.2.24-0ubuntu0.18.04.1 | server-side, HTML-embedded scripting language (PHPDBG binary) |
linux-modules-4.15.0-70-generic | 4.15.0-70.79 | Linux kernel extra modules for version 4.15.0 on 64 bit x86 SMP | |
libpython2.7-minimal:amd64 | 2.7.15-4ubuntu4~18.04.1 | 2.7.15-4ubuntu4~18.04.2 | Minimal subset of the Python language (version 2.7) |
systemd | 237-3ubuntu10.29 | 237-3ubuntu10.31 | system and service manager |
python3-apport | 2.20.9-0ubuntu7.7 | 2.20.9-0ubuntu7.9 | Python 3 library for Apport crash report handling |
php7.2-common | 7.2.19-0ubuntu0.18.04.2 | 7.2.24-0ubuntu0.18.04.1 | documentation, examples and common module for PHP |
base-files | 10.1ubuntu2.6 | 10.1ubuntu2.7 | Debian base system miscellaneous files |
clamav-freshclam | 0.100.3+dfsg-0ubuntu0.18.04.1 | 0.101.4+dfsg-0ubuntu0.18.04.1 | anti-virus utility for Unix - virus database update utility |
php7.2-ldap | 7.2.19-0ubuntu0.18.04.2 | 7.2.24-0ubuntu0.18.04.1 | LDAP module for PHP |
libisccc160:amd64 | 1:9.11.3+dfsg-1ubuntu1.9 | 1:9.11.3+dfsg-1ubuntu1.10 | Command Channel Library used by BIND |