In this tutorial, I will be installing and configuring snare agent on hosts for monitoring them with OSSIM Open-source SIEM.
Let’s get started…
– Download Snare Client edition from: sourceforge.net/projects/snare/
– Enable Snare Plugin on OSSIM Server by
– Select option “snare“, select OK
– Select Back
– Select “Apply Settings“, it will take some time to complete.
Installing Snare Agent on Windows Client:
– Current latest file Downloaded is “SnareForWindows-4.0.2.0-MultiArchOpenSource.exe”
– Execute downloaded “SnareForWindows-XXXX-MultiArchOpenSource.exe“.
– Select option “Yes” when setup asks about to “Takeover Control of logs” as shown below:
– Select “Use System Account” as recommended or provide any Windows Log reading level account for Snare. Shown below is selection of using System Account.
– Select “Enable Web Access” on next screen and provide password for Web Access Snare panel as shown below:
– Remember, Username is by default: snare and Password is what we have entered in this step.
– Access Snare Client Web interface in Web Browser at following URL:
– http://localhost:6161
– Web interface will be shown as below:
– Change following options in it:
– Set Port to 514
– Enable Option: “Enable Syslog Header”
– Apply Settings
– Open Registry Editor and goto following address:
– Double Click “Delimeter” and enter SemiColon “;” (without quotes) and click OK.
> net start snare
Configure Snare on OSSIM Server:
– Jailbreak the System and edit “/etc/ossim/agent/plugins/snare.cfg”
– Do following changes:
– Add Line: location=/var/log/syslog
– Now Snare should be shown in “Data Sources” Drop Down Menu in Analysis > Security Events (SIEM), as shown below:
– Now, when I tried to login to Snare Monitored host WinXP-1-21, I’ve got Snare alerts in this Menu as shown below:
Installing Snare Agent on Linux client:
– Download Snare for linux from:
– x86: http://downloads.sourceforge.net/project/snare/Snare%20for%20Linux/2.1.0/SnareLinux-2.1.0-1.i686.rpm
– x64: http://downloads.sourceforge.net/project/snare/Snare%20for%20Linux/2.1.0/SnareLinux-2.1.0-1.x86_64.rpm
– Add OSSIM Server’s IP in Output Destination with port 514 after colon as shown below:
– Restart snare service after changing configuration.
Thank you for this tuto
Perfect tutorial and great peace of work , so helpful and clear .. thank you so much
i would seize the opportunity to ask you if current version of snare opensource version has support for windows server 12R2 ?
This site really has all of the information and facts I needed
about this subject and didn’t know who to ask.
Hi Cialis,
What do you need to know, please reply ?
Hi , I would like to thank you for your effort . I just have some problem in the installation . I did all the steps but i didn’t fid snare in DATA Sources and I really don’t know why . Hope you can help me. Thank you
Hi,
What error are you facing exactly ?
Regards.