Release Notes for Snare Central v8.8.0
Snare Central v8.8.0 was released on 21st May 2026.
Snare Central incorporates Reflector v3.4.0, Snare Agent Manager (SAM) v2.2.1, and Snare Enterprise Agent for Linux v5.10.1.
If the threat intelligence component is active, version 6.8.7 of ElasticSearch is activated.
The following licensed components are available:
Snare Management Center (SMC)
Snare Management Center Client (SMC)
Agent Management Console (AMC)
Snare Advanced Analytics (SAA)
Cloud Logs Collection:
Office 365 Logs Collection
Amazon Web Services Log Collection
Oracle Cloud Log Collection
After upgrading to Snare Central v8.8.0, please reboot the server to apply kernel changes, as advised by Ubuntu.
Overview
Snare Central version 8.8.0 introduces new Log Aggregation / De-duplication capability in Snare Reflector, Field Remapping enhancements, Events Replay to Microsoft Sentinel, new Manage Certificates page, and a range of other improvements and fixes.
Please refer also to Release Notes for Snare Agent Manager v2.2.1
Compatibility Note
Snare Agent Management v2.2.1 included in this version of Snare Central is compatible with the following versions of Snare Agent.
SAM v2 Feature | Supported Snare Agent Versions |
|---|---|
Agent Configuration Management | 5.8.0 or newer |
Agent License Management | 5.5.0 or newer |
Remote Agent Upgrade | 5.5.0 or newer |
Agents Discovery using Network Scan | 5.4.0 or newer |
Please upgrade the Snare Agents to the latest version BEFORE upgrading the Snare Central, if you are using these features of SAM.
Features and Enhancements
Event Aggregation / De-duplication
Introduced support for aggregating duplicate or similar events from the same source into a single event within a configurable time window.
Aggregation rules can be defined in Destination Configuration based on Log Type and Event IDs or specific Field values. This reduces data volume sent to destinations while preserving full event details and enriching events with aggregation metadata. All event formats are supported.
Please see the User Guide https://prophecyinternational.atlassian.net/wiki/x/RwBf3Q > Aggregation sectionExample of Aggregation Rules in Destination ConfigurationFields Remapping
Fields remapping can now be applied to events in two additional destination formats:
Syslog 5424 JSON
Generic JSON
Enhanced default remapping template for Windows events sent to Splunk CIM in Splunk HEC format
Added "Send/Do Not Send Unmapped Fields" switch for each Log Type in a remapping template configuration
Added a new RegexExtract field remapping function allowing to extract values from the event based on a regular expression
Reflector Configuration file format improvements
Events Replay to Microsoft Sentinel destination is now supported
New Manage Certificates page was added in Reflector UI allowing to upload, view and delete certificates.
Please see the User Guide Manage CertificatesmTLS certificates upload was migrated to the Manage Certificates page, and mTLS destination configuration was updated to select already uploaded client certificate
Introduced unique Destination identifier not relying on destination name or details
Benefits include:Creation of multiple destinations with the same connection details is now allowed, catering for multiple cloud tenancies and endpoints.
A warning message is displayed in case a destination with the same connection details already exists.Destination statistics are retained when destination is renamed or its connection details are changed
‘Destination Name’ field now accepts spaces and special characters
‘Replay Task Name’ field now accepts spaces and special characters
For Splunk HEC and Microsoft Sentinel destinations, the ‘IP/Hostname’ field is now more lenient and allows to have protocol prefix http:// or https://
Destination graphs on the Reflector Dashboard now display the Destination Name as part of the title
Events or Bytes per second graph on Executive Dashboard now displays Destination Names in the legend
Improved event queries performance and resilience for high volume of data
Improved the rate of forwarding events to Priority Destination
Improved validation of SSO provider configuration before it can be enabled
Ensuring that latest groups are used once SSO provider gets enabled. Additionally, when SC Administrator logs in and there's an enabled SSO provider, SC will fetch groups from the SSO provider, ensuring that latest groups will be used and configured
Added a configurable Agent Event Volumes Sensitivity setting in Health Checker configuration, allowing users to tune event‑surge alert triggers in the "Show Agent Event Volumes" section (1σ–3σ, default is 2σ. Increase the value to see less alerts)
Notifications email address in the Wizard > High Availability section can now be edited even after the High Availability is enabled
Improved Auto-Remove functionality to prevent noisy warnings
Added email body content for consolidated report emails
Removed redundant Additional Objectives section in Configuration Wizard which had the same function as System > Administrative Tools > Import Objectives
Added friendly message "Click on a heat map cell to view the pie chart" when a pie chart section of the Heatmap is manually expanded, but no data is selected
Security
System packages updated to mitigate security vulnerabilities.
After upgrading to Snare Central v8.8.0, please reboot the server to apply kernel changes, as advised by Ubuntu.
Improved input data validation when creating new local users
Improved handling of certificates for mTLS destinations
Strict Certificate Checking can now be enabled in Reflector configuration to verify entire certificate chain
Bug Fixes
Resolved the issue where the Replay Task form was automatically resetting every minute
Added IP uniqueness validation in Snare High Availability configuration, to prevent misconfiguration
Fixed SNMP Test failure when community name contains special characters
Fixed display and error message truncation issues for Email Server Setup when TLS protocol is selected
Fixed the issue with Executive Dashboard graphs showing no data due to query timeout
Improved clean up of indexes and metadata corresponding to the events deleted through Auto-Remove task
Fixed the issue with Reports not completing if SnareStore service was terminated or disrupted
Fixed Upgrade process errors and an issue that allowed simultaneous updates to be executed
Improved File Integrity Check report in Health Checker to filter out files that change on normal operation
Fixed an issue where Real Time Alerts could occasionally fail to decode a JSON message if Snare Original Event was enabled in Reflector
Fixed an issue where applying a remote Elastic instance in the SATI was breaking Reflector configuration
Improved resilience of Agent Status collection from cron job if directory permissions got corrupted
Fixed an intermittent crash in Reflector during service startup caused by concurrent access to shared statistics map
Fixed an issue where Snare services could fail to restart automatically after failure, causing log collection to halt
Fixed erroneous display of the login screen instead of the dashboard for a few seconds, after logging in with identity provider account
Fixed issue of custom groups not being displayed in “Grant full access to” dropdown in Analytics Dashboard configuration
User Guides
Up-to-date online documentation is available here:
Offline versions related to this release: