Reflector Settings

Reflector Settings

Settings

This menu section consolidates General settings, License information and Listeners ports list of the Snare Reflector.

General

image-20260217-230014.png


The following options may be configured on the Reflector > Settings > General page:

  • Web Management Port  - The port the Snare Reflector web UI operates on. It is recommended that this value stay at the default value (6111) when the reflector is operating as part of a Snare Central installation.

  • Web UI HTTPS Certificate - This certificate will be used for HTTPS Snare Reflector Web UI interactions. By default, an auto-generated self-signed certificate is used.

  • TLS Listener Certificate - This certificate will be used for TLS client interactions.

  • Generate a new Self-Signed Certificate - Newly generated self-signed certificates will be appended to the list of available certificates.

  • Network Destination certificate verification - Choose the desired level of certificate verification.  This can be one of Accept Any or Strict Checking. Accept Any is ideal for self-signed certificates. Strict Checking verifies the entire certificate chain. Strict Checking option may be unavailable in some versions of Snare Central.

  • UTC Charts - Turn this on to display UTC (Coordinated Universal Time) time on destination charts instead of local machine time.  By default the times are displayed in local time.

  • TLS Authentication Key - Define the authentication key for TLS_AUTH listener. The same key should be used by the Snare Agent that wants to send logs using TLS_AUTH protocol.
    TLS_AUTH is Snare proprietary protocol that supports TLS connection with authentication between source and destination. 

  • Enable Log Aggregation - Turn this on to enable log aggregation feature and allow configuration of aggregation rule for destinations. Log aggregation is a feature in Reflector, which accumulates incomming events and forward similar/duplicate events arrived within a defined time window as a single aggregated event.

  • Enable Original Event - Allow storing an original raw copy of each received event log. This setting has to be turned ON for the ability to replay logs in the future. This, however, will increase storage usage of Snare Archive.
    This setting is turned OFF by default for upgrades, and turned ON by default for fresh installations.

  • Enable Event Replay - Turn this on to configure and run an event Replay task. Replay runs as a separate service, and can be turned off when not in use. 

    Only events collected while Enable Original Event was ON can be replayed to the destination. 

To save and set the changes to the above settings, and to ensure the Reflector service has received the new configuration, perform the following:

  1. Click on Update to save any changes. 

  2. In the Confirmation Dialog click Confirm.



    Snare Reflector needs to be restarted for the settings changes to take effect. Events received via UDP connection may be lost during service restart.

  3. Click on the Restart Snare Reflector button at the top of the screen to restart the service and apply the changes.


License

Reflector > Settings > License page displays the licensing information for the Snare Reflector and includes:

  • The Key IDs for your local host, where Snare Central is installed

  • The active licenses registered to your organization

Listeners

Reflector > Settings > Listeners page displays the ports and protocols on which the Snare Reflector is listening for incoming events.

All Listeners are currently locked by the Snare Central collection server. 

About

Reflector > About page contains basic information about the Snare Reflector, including:

  • Version - version of Snare Reflector

  • Build - Snare Reflector build ID

  • Uptime - length of time Snare Reflector is online, since the last service restart

  • Server Time - time on the Reflector server

  • Client Time - time on the browser server

  • Time Drift - clock drift between the client and server. It is important to ensure there is no time drift of more than ten seconds, as it may prevent logging into the Snare Reflector.


Fixing time drift

If you do experience time drift please check:

  • the date time on the server where the reflector is installed

  • the date time on the client where you are accessing the browser.

Update the times as necessary then restart the browser and try again.

Help

Reflector > Help page links to the Reflector section in the User Guide, which provides detailed information on configuring and monitoring Snare Reflector.