The console

Sources

The collectors on this machine, and every option in the add-source wizard.

A source is one collector: a set of Windows Event Log channels, a file or glob, a set of watched paths, or a network port that receives from other devices.

The Sources page
The Sources page

The list

Filter chips across the top narrow the list by type — Windows Event Log, Log File, File Integrity, Syslog, NetFlow.

Each row shows:

ColumnWhat it tells you
Name and typeThe name you gave it
HealthSee below
RateEvents a second right now
SwitchPause or resume collection

Health

StateMeaning
HealthyCollecting normally
RestartingFailed and being restarted automatically
QuarantinedFailed repeatedly and stopped, so it cannot affect anything else
StoppedNot running
PausedYou switched it off
PendingConfigured but not yet applied
Not appliedStaged, waiting for you to apply

Pausing

The switch pauses collection for that source. Windows keeps the events in its own log while you are paused, so resuming picks up from where you stopped rather than skipping the gap — within the limits of the channel's own size.

Pausing is a staged change like any other.

Row actions

The ⋯ menu on each row:

ActionWhat it does
Edit sourceReopen the wizard on this source
Send test eventPush one synthetic event through the pipeline to a destination, to prove the path end to end
Stream live eventsJump to Live stream filtered to this source
Re-baseline…File-integrity sources only — see below
Delete sourceRemove it

Send test event

Useful when you have configured a destination and want to know whether it works before waiting for real traffic. The event is marked as a test, travels the whole pipeline including masking, and arrives at the destination you choose.

Re-baseline

For a file-integrity source, the baseline is the recorded state of the files it watches. Changes are reported against it.

Re-baselining accepts the current state as the new normal — do it after a planned change, such as a patch or a deployment, so the next scan does not report the whole change set again. You can re-baseline one watch item or all of them. Either way, the action is recorded in the audit log.

Adding a source

+ Add source opens the wizard.

Choosing what to collect
Choosing what to collect

You can start from a template — a ready-made source for a common case, such as Windows security essentials, IIS logs, DNS query logs, DHCP audit logs, SQL Server error logs or Exchange logs — or start blank and choose the type yourself.

Templates tell you exactly what they will read, and warn you where the source needs to be switched on in Windows first.

Windows Event Log

The Windows Event Log source form
The Windows Event Log source form
SettingWhat it does
Source nameSuggested from your choice, and it keeps updating until you edit it.
ChannelsThe channels to collect — one source collects them all. Pick from the offered set, or use More channels to choose any channel on the machine, including custom ones.
SeverityAll events, Warning & above, or Errors only. The agent compiles this into the channel's own filter, so events below the level are never read.
Event IDs to includeCollect only these. Ranges are allowed. Leave it blank to collect all.
Start collectingNew events only (the default), or Also read existing events to take the log's existing backlog on first save.

Under Advanced settings you will also find the remaining options for the source, including excluding event IDs, restricting to named providers, supplying your own event query in place of the filters above, message rendering, and throughput tuning. The defaults suit most machines.

Message rendering is the one worth knowing about: it resolves each event's human-readable message text. Off is fastest; turn it on when your receiver expects rendered text — a Snare collector's category column, for instance.

Filtering here is the cheapest filtering available — the events are never read in the first place. Prefer it over a pipeline filter when you know a whole event ID is of no interest.

Log file on disk

The log-file source form
The log-file source form
SettingWhat it does
File path or globA file, or a wildcard such as C:\logs\app*.log. New matching files are picked up; rotated files are followed.
Detect formatSamples the file and suggests the encoding.
EncodingAuto-detect, UTF-8, UTF-16 LE or UTF-16 BE. Auto-detect handles most files, including the UTF-16 ones some Windows products write.
Start collectingNew lines only, or Also read existing content to take the file you already have.

Include and exclude patterns, and the remaining tuning, are under Advanced settings.

File integrity

The file-integrity source form
The file-integrity source form

Each watch item is a path and a schedule:

SettingWhat it does
Location to watchA file, a folder, or a wildcard.
Include subfoldersWalk the tree below it.
Scan frequencyEvery 15 min, Hourly or Daily.
Large filesAbove the size you choose, track the file by its properties — size, timestamps, permissions — rather than by reading it, so one very large file cannot dominate a scan.

Include and exclude patterns are under Advanced settings.

Changes are reported as events like any other, so they flow through your pipeline to your SIEM.

Syslog and NetFlow receivers

For collecting from other devices — firewalls, switches, appliances.

SettingWhat it does
Listen portThe port to receive on — conventionally 514 for syslog, 2055 for NetFlow.
ProtocolSyslog: UDP or TCP. NetFlow: UDP (v5 + IPFIX) or TCP (IPFIX).
Allowed networksWhich addresses may send. Set this. Left empty, the receiver accepts from anything that can reach the port.

Each enabled receiver uses a licence seat. See Licensing.

Remember the firewall: Windows will not let traffic reach the port until you allow it.

Saving

Save stages the source and enables it. Save without enabling stages it switched off — useful when you are preparing a configuration you do not want running yet.

Either way, nothing happens until you review and apply. See Using the console.