Saturday , March 17 2018
Home / Information Security / Installing and Configuring Snare Agent on Hosts

Installing and Configuring Snare Agent on Hosts

Print Friendly

In this tutorial, I will be installing and configuring snare agent on hosts for monitoring them with OSSIM Open-source SIEM.

Let’s get started…

– Download Snare Client edition from:   
– Enable Snare Plugin on OSSIM Server by

Console Menu  >  Configure Sensor   >   Configure DataSource Plugins.
– Select option “snare“, select OK
– Select Back
– Select “Apply Settings“, it will take some time to complete.




Installing Snare Agent on Windows Client:

– Current latest file Downloaded is “SnareForWindows-
– Execute downloaded “SnareForWindows-XXXX-MultiArchOpenSource.exe“.
– Select option “Yes” when setup asks about to “Takeover Control of logs” as shown below:

– Select “Use System Account” as recommended or provide any Windows Log reading level account for Snare. Shown below is selection of using System Account.

– Select “Enable Web Access” on next screen and provide password for Web Access Snare panel as shown below:

– Remember, Username is by default: snare   and Password is what we have entered in this step.
– Access Snare Client Web interface in Web Browser at following URL:
– http://localhost:6161
– Web interface will be shown as below:

– Change following options in it:

Destination Address  — It will be OSSIM’s Logs Interface IP Address, as in my case it is
Set Port to 514
– Enable Option:  “Enable Syslog Header
Apply Settings

– Open Registry Editor and goto following address:

> HKEY_LOCAL_MACHINE > SOFTWARE > Intersect Alliance > Audit Service > Config
– Double Click “Delimeter” and enter SemiColon “;” (without quotes) and click OK.

– Execute following commands:

> net stop snare
> net start snare

Configure Snare on OSSIM Server:

– Jailbreak the System and edit “/etc/ossim/agent/plugins/snare.cfg
– Do following changes:

Comment out:  location=/var/log/snare.log
Add Line:        location=/var/log/syslog
– Restart OSSIM Agent:
 # /etc/init.d/ossim-agent restart

– Now Snare should be shown in “Data Sources” Drop Down Menu in   Analysis Security Events (SIEM), as shown below:

– Now, when I tried to login to Snare Monitored host WinXP-1-21, I’ve got Snare alerts in this Menu as shown below:


Installing Snare Agent on Linux client:

– Download Snare for linux from:
– x86:
– x64:

# rpm -Uvh SnareLinux-2.1.0-1.i686.rpm
 if error:      perl(Time::HiRes) is needed by SnareLinux-2.1.0-1.i686
# yum install -y perl-Time-HiRes


# vim /etc/snare.conf
– Add OSSIM Server’s IP in Output Destination with port 514 after colon as shown below:

– Restart snare service after changing configuration.

#  service auditd restart 

About Muhammad Attique

  • hamza

    Thank you for this tuto

  • ahmegen .

    Perfect tutorial and great peace of work , so helpful and clear .. thank you so much
    i would seize the opportunity to ask you if current version of snare opensource version has support for windows server 12R2 ?