Release Notes for Snare Central v8.5.0
Snare Central v8.5.0 was released on 24th August 2022.
Snare Central incorporates Reflector v3.1.0, Snare Agent Manager (SAM) v1.6.0, and Snare Enterprise Agent for Linux v5.6.0.
If the threat intelligence component is active, version 6.8.7 of ElasticSearch is activated.
The following licensed components are available:
Snare Management Center (SMC) - new
Snare Management Center Client (SMC) - new
Agent Management Console (AMC)
Cloud Logs Collection: - new
Office 365 Logs Collection - new
Overview
Snare Central version 8.5.0 introduces several new capabilities including Snare Management Center, Cyber Network Map, Office365 logs collection, over 100 new reports and a number of other enhancements and bug fixes.
Features and Enhancements
Snare Management Center
Licensed Feature
Requires license feature Snare Management Center (SMC) for managing server, and Snare Management Center Client (SMC) for each of the managed servers
New capability to monitor and manage multiple remote Snare Central servers.
This includes:Viewing system health status of remote Snare Central servers and server groups
Viewing dashboard, alerts and history of a remote server
Remote Management Mode for modifying configuration of a remote server via local UI
Synchronising configuration of the primary server with other servers in the group
Please refer to the User Guide > System Menu > Administrative Tools > Snare Management Center for detailed documentation.
Cyber Network Map
Real-time map of activity based on live network-related events. An interactive 3-D globe and a world map provide the capability to visualize and explore the geo-located source and destination data associated with a range of firewall, router and web-related logs.
Data tables display key event component statistics such as country of origin, source and destination IP addresses, ports, and more. Only the following log types are available for this release other log types will be added over later releases. Supports Cisco ASA(PIX), Cisco FTDLog (IPS), IIS/Apache Web Log, PanFirewall (PaloAlto), and IPtablesFirewallLog from Unix logs.
Click on the statistic metric to review relevant events on Event Search page in a new browser tab.
As some events may include local internal (RFC1918 addresses such as 10.1.1.1) network IP addresses or hostnames which wont have a native geolocation address to plot, so in order to correctly place them on the map user can configure their geo-location mapping on System > Administrative Tools > Configure GeoLocation for Mapping page for their correct physical location.Office 365 Log Collection module
Licensed Feature
Requires license feature Office 365 Logs Collection or Cloud Logs Collection bundle feature.
For instructions on how to configure log collection from Office 365 Management Activity API in Snare Central, please refer to the User Guide > Collection Subsystem > Office 365 Logs Collection.
there are 41 new cloud reports for Office 365 and Azure cloud logs.
Extended collection subsystem to support more Cisco Firepower Threat Defence (IPS) log types:
- WebVPN and AnyConnect Client logs
- SSL VPN Client logs
- Command Interface logs
- VPN Load Balancing logs
- EIGRP Routing logs
- Failover logs
- IP Stack logs
- OSPF Routing logs
- IKE and IP Sec logs
- other Cisco FTD logs (generic CiscoFTDLog type)
For details on the Cisco FTD log types and sub-types please refer to the User Guide: Log Types: Cisco FTD
50 new out-of-the-box reports were added for Cisco Firepower Threat Defence LogsAdded 9 new out-of-the-box reports for Linux Logs received in Snare v2 format
Updated 7 and added 2 new out-of-the-box reports for Linux Logs received in Snare format
Added handling for Centripetal logs
Added Enable Realtime Alerts global control under System > Administrative Tools > Configuration Wizard > Performance and Hardware.
NOTE: By default real time alerts will be disabled with this patch.
If a customer is using real time alerts then they will need to enable this check box and select the NEXT button to save for real time alerts to continue to alert as expected.
Added Disable TLSv1.2 option under Configuration Wizard > Security Setup > TLS Controls so only TLS 1.3 will be used.
Added outgoing CEF format support to reflector for Windows events received in Snare v2 format, and for Cisco ASA firewall logs. For other log sources, generic CEF field population is available
Enhancement to Backup and Restore functionality to support persistent NAS mounts. "Mount Permanently" checkbox was added on the Select Storage Device screen
The Manage Objective Schedules objective in System Administrative tools, now includes a CSV export capability
Syslog RFC 5424 logs that use milliseconds and hour-based delta time-zone offsets are now supported
Increased the size of the regular expression field in the Autoremove objective from 20 to 40
Added a warning in the Health Checker when license is about to expire
Access to the Dashboard can be limited via access controls. Users who have no permissions to access the dashboard will be presented with a generic page after logging in
Dashboard heatmap table look and feel has been updated to match other tables for consistency
Clicking on a heatmap table row opens a pop-up with all event content
Event Search accessibility improvement: In the drop down selectors, Select All checkbox can be selected/deselected by pressing ALT+ENTER. Pressing ENTER selects/deselects the active item in the dropdown. There is also a temporary change in functionality on Event Search that will not show highlighting due to a potential security vulnerability in parsing the data. This highlighting option will be reinstated in a later update.
Reflector UI was restyled to match the Snare Central look and feel
When disk space is below user-defined thresholds for the SnareArchive or SnareTransition partitions, the query subsystem will remain functional, and will no longer be turned off along with collection