Snare is a long-established Windows event format that many collectors accept. DPLens can emit it, so a collector already configured to receive Snare records can receive from DPLens.
destinations:
- type: tcp
name: snare-collector
params:
address: "collector.example.com:514"
format: "snare"
severity: "5"
hostname: "CORP-FS01"
Snare is a trademark of its owner. DPLens is not affiliated with or endorsed
by it. The name is used here only to say what DPLens interoperates with.
| Format | What it produces |
|---|---|
snare | Snare's tab-separated fields |
snare-3164 | The same fields inside an RFC 3164 syslog line, for collectors that expect a syslog wrapper. This is what the console's Snare receiver preset selects. |
Transport
Any of TCP, TLS or UDP. TCP on port 514 is the usual choice for a Snare collector; use type: tls where the collector supports it.
- type: tls
name: snare-collector
params:
address: "collector.example.com:6514"
format: "snare"
ca_file: "C:\\ProgramData\\DPLens\\ca\\collector-ca.pem"
framing: "octet-counted"
Getting the fields populated
Snare records carry a category column that comes from the event's task display name. That name only exists once the event's message has been resolved, so if you want that column filled in, turn on message rendering for the source:
- In the console: Sources → your source → Advanced settings → Message rendering, set to the Snare option.
- In configuration:
render: "snare"on the Windows Event Log source.
Without it the column is empty. Rendering costs CPU, so turn it on because your collector needs it, not by default.
Settings
| Setting | What it sets | Default |
|---|---|---|
severity | The severity in the record | 5 |
hostname | The host name in the record | This machine's name |
criticality | Snare's criticality value | 0 |
facility | Only used by snare-3164 | 1 |
Replacing an existing Snare agent
- Configure DPLens alongside the existing agent, pointed at the same collector.
- Compare what arrives from each for a period you are comfortable with.
- Stop the old agent.
- Remove it.
Run both only long enough to satisfy yourself: while both are running your collector receives every event twice.
Note that DPLens does not emit another agent's own internal telemetry, so if your collector has content that keys on it, that content will have nothing to read.
Checking it works
Use Send test event from a source's row menu, then watch Live stream with this destination selected: you see the exact record, tabs and all, that the collector receives.