Release Notes for Snare Central v8.6.0
Snare Central v8.6.0 was released on 16th May 2024.
Snare Central incorporates Reflector v3.2.0, Snare Agent Manager (SAM) v2.0.0, and Snare Enterprise Agent for Linux v5.8.0.
If the threat intelligence component is active, version 6.8.7 of ElasticSearch is activated.
The following licensed components are available:
- Snare Management Center (SMC)
- Snare Management Center Client (SMC)
- Agent Management Console (AMC)
- Snare Advanced Analytics (SAA) - new
- Cloud Logs Collection:
- Office 365 Logs Collection
- Amazon Web Services Log Collection - new
- Oracle Cloud Log Collection - new
Overview
Snare Central version 8.6.0 introduces several new capabilities including Snare Analytics Dashboards (pre-built and custom), logs collection from Azure, AWS and Oracle Cloud Infrastructure, integration with Okta, over 180 new reports and a number of other enhancements and bug fixes.
Compatibility Note
Snare Agent Management v2.0.0 included in this version of Snare Central is compatible with the following versions of Snare Agent.
SAM v2 Feature | Supported Snare Agent Versions |
---|---|
Agent Configuration Management (New) | 5.8.0 or newer |
Agent License Management | 5.5.0 or newer |
Remote Agent Upgrade | 5.5.0 or newer |
Agents Discovery using Network Scan | 5.4.0 or newer |
Please upgrade the Snare Agents to the latest version BEFORE upgrading the Snare Central, if you are using these features of SAM.
After upgrading to Snare Central v8.6.0, please reboot the server to apply kernel changes, as advised by Ubuntu.
This version of Snare Central removes OpenVAS from the system. If you currently use this software then you will need to seek alternatives. The version we had installed has now become to hard to maintain and update. Some similar functions will be looked at in the future given the new analytics features in Snare Central.
Features and Enhancements
Snare Analytics Dashboards
Licensed Feature
This requires the Snare Advanced Analytics (SAA) or Snare Advanced Threat Intelligence (SATI) license features
Visualise the data you collect to gain security insights and discover issues early!
This new capability combines the power of Events Search, where you can construct, test and save log data queries, with the visual components you can use to visualise the results.
Create pie charts, bar charts, line charts, tables and cards to build your own dashboard, or use one of the 26 pre-built Analytics Dashboards that are available out of the box.
Dashboard components can be arranged in a grid-style pattern, and resized to highlight the importance of the information.
Components can be linked to visualise different perspectives on the same data query.
Please refer to the User Guide > Analytics Dashboards for detailed documentation.26 pre-built dashboards are available under Analytics Dashboards:
- Log collection from Cloud Providers
Snare Central now allows to actively collect logs from a variety of the supported cloud providers:
- Amazon Web Services (AWS)
- Azure Cloud
- Microsoft 365
- Oracle Cloud Infrastructure
A new user interface is provided for configuring and monitoring event log collection: System > Administrative Tools > Cloud Log Collection Configuration
Reports and dashboards for the new log types are available out-of-the-box. Details are provided below.
Supported cloud providers:Microsoft 365
Licensed Feature
This capability requires either Office 365 Logs Collection (IA_CLOUD_O365) or Cloud Logs Collection (IA_CLOUD) license features
Snare Central can collect activity logs from the Office 365 Management Activity API, including user, admin, system, and policy actions and events from Office 365 (rebranded to Microsoft 365) activity logs.
This capability was first introduced in Snare Central v8.5.0.
In this release, scalability and stability of the collection process were significantly improved.
A new user interface is now available to configure log collection from the Office 365 Management Activity API.For instructions on how to configure log collection from Office 365 Management Activity API, please refer to the User Guide > Microsoft 365 - Cloud Log Collection Configuration
Azure Cloud
Licensed Feature
This capability requires either Office 365 Logs Collection (IA_CLOUD_O365) or Cloud Logs Collection (IA_CLOUD) license features.
Snare Central can be configured to collect activity logs from the Azure Log Analytics Workspace API.
For instructions on how to configure log collection from Azure Cloud in Snare Central, please refer to the User Guide > Microsoft Azure - Cloud Log Collection Configuration
Azure logs will be classified in Snare Central as documented here: User Guide > Log Types: Azure
There are 59 new reports available out-of-the box for Azure cloud logs.
Amazon Web Services
Licensed Feature
This capability requires either Amazon Web Services Log Collection (IA_CLOUD_AWS) or Cloud Logs Collection (IA_CLOUD) license features.
Snare Central is capable of collecting logs from the AWS Kinesis Data Streams via the Kinesis Data Streams API.
For instructions on how to configure log collection from AWS Kinesis Data Stream, please refer to the User Guide > Amazon Web Services (AWS) - Cloud Log Collection Configuration
AWS logs will be classified in Snare Central as documented here: User Guide > Log Types: AWS
There are 13 new reports available for AWS logs.
Oracle Cloud Infrastructure
Licensed Feature
This capability requires the Oracle Cloud Log Collection(IA_CLOUD_ORACLE) or Cloud Logs Collection (IA_CLOUD) license features.
Snare Central can be configured to collect audit logs from the Oracle Cloud Infrastructure (OCI).
For instructions on how to configure log collection from Oracle Cloud Infrastructure, please refer to the User Guide > Oracle - Cloud Log Collection Configuration
Oracle Cloud logs will be classified in Snare Central as documented here: User Guide > Log Types: Oracle Cloud Infrastructure
There are 25 new reports available for Oracle Cloud logs.