Tuesday , April 20 2021

Installing and Configuring Snare Agent on Hosts

In this tutorial, I will be installing and configuring snare agent on hosts for monitoring them with OSSIM Open-source SIEM.

Let’s get started…

– Download Snare Client edition from:             sourceforge.net/projects/snare/
– Enable Snare Plugin on OSSIM Server by

Console Menu  >  Configure Sensor   >   Configure DataSource Plugins.
– Select option “snare“, select OK
– Select Back
– Select “Apply Settings“, it will take some time to complete.




Installing Snare Agent on Windows Client:

– Current latest file Downloaded is “SnareForWindows-
– Execute downloaded “SnareForWindows-XXXX-MultiArchOpenSource.exe“.
– Select option “Yes” when setup asks about to “Takeover Control of logs” as shown below:

– Select “Use System Account” as recommended or provide any Windows Log reading level account for Snare. Shown below is selection of using System Account.

– Select “Enable Web Access” on next screen and provide password for Web Access Snare panel as shown below:

– Remember, Username is by default: snare   and Password is what we have entered in this step.
– Access Snare Client Web interface in Web Browser at following URL:
– http://localhost:6161
– Web interface will be shown as below:

– Change following options in it:

Destination Address  — It will be OSSIM’s Logs Interface IP Address, as in my case it is
Set Port to 514
– Enable Option:  “Enable Syslog Header
Apply Settings

– Open Registry Editor and goto following address:

> HKEY_LOCAL_MACHINE > SOFTWARE > Intersect Alliance > Audit Service > Config
– Double Click “Delimeter” and enter SemiColon “;” (without quotes) and click OK.

– Execute following commands:

> net stop snare
> net start snare

Configure Snare on OSSIM Server:

– Jailbreak the System and edit “/etc/ossim/agent/plugins/snare.cfg
– Do following changes:

Comment out:  location=/var/log/snare.log
Add Line:        location=/var/log/syslog
– Restart OSSIM Agent:
 # /etc/init.d/ossim-agent restart

– Now Snare should be shown in “Data Sources” Drop Down Menu in   Analysis Security Events (SIEM), as shown below:

– Now, when I tried to login to Snare Monitored host WinXP-1-21, I’ve got Snare alerts in this Menu as shown below:


Installing Snare Agent on Linux client:

– Download Snare for linux from:
– x86:    http://downloads.sourceforge.net/project/snare/Snare%20for%20Linux/2.1.0/SnareLinux-2.1.0-1.i686.rpm
– x64:    http://downloads.sourceforge.net/project/snare/Snare%20for%20Linux/2.1.0/SnareLinux-2.1.0-1.x86_64.rpm

# rpm -Uvh SnareLinux-2.1.0-1.i686.rpm
 if error:      perl(Time::HiRes) is needed by SnareLinux-2.1.0-1.i686
# yum install -y perl-Time-HiRes


# vim /etc/snare.conf
– Add OSSIM Server’s IP in Output Destination with port 514 after colon as shown below:

– Restart snare service after changing configuration.

#  service auditd restart 

About Muhammad Attique

Check these out :)

How to Install & Configure Google Chrome on Kali Linux

In this blog post, I’m going to demonstrate step by step how to install & …


  1. Thank you for this tuto

  2. Perfect tutorial and great peace of work , so helpful and clear .. thank you so much
    i would seize the opportunity to ask you if current version of snare opensource version has support for windows server 12R2 ?

  3. This site really has all of the information and facts I needed
    about this subject and didn’t know who to ask.

  4. Hi , I would like to thank you for your effort . I just have some problem in the installation . I did all the steps but i didn’t fid snare in DATA Sources and I really don’t know why . Hope you can help me. Thank you

Leave a Reply to Muhammad Attique Cancel reply

Your email address will not be published. Required fields are marked *

For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

I agree to these terms.