Snare

-
Ability to change Agent name via Silent Install Parameters
It would be nice to be able to change the agent name via the install parameters. We are using AWS and would like to put our own variables in there to custom name the machine.
1 vote -
Ability to select the different destinations for objects in the Snare Agent
In the Snare agent now you can set multiple destination. Would be helpful if for each object defined in the agent you can set what destination is used or multiple destination.
1 voteThank you for sharing this suggestion, we will review and reach out to you for further clarification if needed. This enhancement is under review with the Snare Development Team.
-
Office 365 Logs to be integrated into Snare via the Office 365 Management API
We are currently moving our office environment to the local server based environment to and Office 365 environment. We would like to be able to collect Office 365 into our SIEM and make auditing easier. Office 365 seems to be the software for many moving forward, especially in the current circumstances of COVID-19 and working remotely.
2 votesThank you for sharing this suggestion, we will review and reach out to you for further clarification if needed. This enhancement is under review with the Snare Development Team
-
Event Trace Log (ETL) - Microsoft DNS Server Analytic Logs
As a Snare Enterprise agent user I desire the ability to read and transmit via syslog Event Trace Log (ETL) files. One example in which this feature would be valuable is the reading and transmission of Microsoft DNS Server Analytic Logs.
1 voteThank you for sharing this suggestion, we will review and reach out to you for further clarification if needed. This enhancement is under review with the Snare Development Team.
-
Enable Snare Agent to automatically select a certificate
The customer must currently select the Certificate to be used.
9 votesThank you for sharing this suggestion, we will review and reach out to you for further clarification if needed. This enhancement is under review with the Snare Development Team.
-
Snare Agent caching for Flat Files
I would like to see a "counter" for the Flat File monitoring by the SAM agent. I understand that the Snare agent is able to resend the logs by resetting the counter inside the target computer's registry. Can we have this for the Flat File Monitoring as well?
1 voteThank you for sharing this suggestion, we will review and reach out to you for further clarification if needed. This enhancement is under review with the Snare Development Team.
-
TLS Mutual Authentication for Windows Snare Agent
Besides plan TLS and TLS Auth, allow TLS Mutual Authentication (where both the agent and destination have certificates and must verify each other).
1 voteThank you for sharing this suggestion, we will review and reach out to you for further clarification if needed. This enhancement is under review with the Snare Development Team.
-
Snare Agents TLS setting to disable TLS CRL verification
most common TLS clients (web browsers) don't check CRLs (cert revocation lists) or do soft failure. It would be nice to do the same in SNARE, so that CRL fetch outage doesnt cause logging outage
2 votesThank you for sharing this suggestion, we will review and reach out to you for further clarification if needed. This enhancement is under review with the Snare Development Team.
-
Customisation of Snare logging formats for different event types (especially for Linux) so our SIEM can understand them
Snare logs when installed on Linux do not send syslog + FIM events in a format that a SIEM like QRadar, Arcsight, AlienVault, Splunk natively understand. This is because the Snare agent re-writes the log. We want to be able to send those logs in their native format or a custom format we choose.This way, we can send Linux logs in their native format and send FIM logs that look different so the SIEM can handle them differently. This is currently why we don't use or recommend Snare for Linux FIM monitoring.
3 votesThank you for sharing this suggestion, we will review and reach out to you for further clarification if needed. This enhancement is under review with the Snare Development Team.
-
1 vote
Thank you for sharing this suggestion, we will review and reach out to you for further clarification if needed. This enhancement is under review with the Snare Development Team.
-
Implement digital signatures for the Snare Agents
Many platforms such as Windows include digital signature management for the software thats installed. Snare currently provided several hash formats to validate the software that is installed. The certificate signing uses signature of signing the agent installer and exe files from a trusted certificate authority that the host already has a trusted signed root certificate in its certificate store. This then helps with OS checks such as smart screen on windows to validate that the software was from a known trusted source, was signed using an EV certificate and has a positive reputation from the industry. This will aid in…
1 voteThank you for sharing this suggestion. This enhancement is in progress with the Snare Development Team.
Further updates will be provided when the release is being packaged.
- Don't see your idea?