Reflector Dashboard
The Reflector Dashboard displays event collection statistics and destination status. The data updates every few seconds.
Event Collection Statistics
The following dashboard items are available:
Destinations - The number of Destinations to which the Snare Reflector is sending events.
Snare Central has several pre-configured internal destinations:
Snare_Internal | 127.0.0.1:6170:TCP - reflects events internally
Snare_Realtime | 127.0.0.1:6171:TCP - disabled by default. Enabled automatically if any real-time outputs are enabled in your Snare Central objectives.
Snare_Elastic | 127.0.0.1:9201:HTTP - disabled by default. Enabled automatically if local delivery to Snare Advanced Threat Intelligence (SATI) is enabled in Snare Central
The administrator can add additional destinations via Settings | Destinations.
Recent Events / Sec - This is the smoothed average number of events received by Snare Reflector per second.
Total Events / 24 Hrs - This is the total number of events received in the past rolling 24 hour window.
Total Bytes / 24 Hrs - This is the total number of bytes received while Snare Reflector has been running.
Disk Cache % Full - This indicates how full disk cache is as a percentage.
Events On Disk - This indicates the number of events currently stored in the disk cache. Note that the disk cache is only enabled for external priority destinations.
Reflector service restart resets the event collection statistics to 0.
Destination Statistics
The dashboard contains an information card for each destination, that includes the destination status, statistics and chart of its activity over a 24 hour period.
Recent EPS Sent - indicates the smoothed average number of events sent to this destination per second.
Recent Bytes/Sec - indicates the smoothed average number of bytes sent to the destination per second.
Rolling 24H Bytes Sent - indicates the number of bytes sent in the past rolling 24 hour window.
Disk Queue % Full - indicates how full each disk queue file is as a percentage.
Reflector service restart resets the destination statistics to 0.
Destination Chart
Each destination's chart displays the number of events per second (left Y axis) and bytes per second (right Y axis) sent over time (X axis). Note that the time is displayed in local machine time. If required, UTC may be enabled and configurable via Settings | General | UTC Charts.
Click on the "Events per Second" or "Bytes per Second" in the legend to toggle the display of this data series.