Destinations

Sending to a Snare collector

The Snare tab-separated format, over TCP, TLS or UDP.

Snare is a long-established Windows event format that many collectors accept. DPLens can emit it, so a collector already configured to receive Snare records can receive from DPLens.

destinations:
  - type: tcp
    name: snare-collector
    params:
      address: "collector.example.com:514"
      format: "snare"
      severity: "5"
      hostname: "CORP-FS01"

Snare is a trademark of its owner. DPLens is not affiliated with or endorsed

by it. The name is used here only to say what DPLens interoperates with.

FormatWhat it produces
snareSnare's tab-separated fields
snare-3164The same fields inside an RFC 3164 syslog line, for collectors that expect a syslog wrapper. This is what the console's Snare receiver preset selects.

Transport

Any of TCP, TLS or UDP. TCP on port 514 is the usual choice for a Snare collector; use type: tls where the collector supports it.

  - type: tls
    name: snare-collector
    params:
      address: "collector.example.com:6514"
      format: "snare"
      ca_file: "C:\\ProgramData\\DPLens\\ca\\collector-ca.pem"
      framing: "octet-counted"

Getting the fields populated

Snare records carry a category column that comes from the event's task display name. That name only exists once the event's message has been resolved, so if you want that column filled in, turn on message rendering for the source:

Without it the column is empty. Rendering costs CPU, so turn it on because your collector needs it, not by default.

Settings

SettingWhat it setsDefault
severityThe severity in the record5
hostnameThe host name in the recordThis machine's name
criticalitySnare's criticality value0
facilityOnly used by snare-31641

Replacing an existing Snare agent

  1. Configure DPLens alongside the existing agent, pointed at the same collector.
  2. Compare what arrives from each for a period you are comfortable with.
  3. Stop the old agent.
  4. Remove it.

Run both only long enough to satisfy yourself: while both are running your collector receives every event twice.

Note that DPLens does not emit another agent's own internal telemetry, so if your collector has content that keys on it, that content will have nothing to read.

Checking it works

Use Send test event from a source's row menu, then watch Live stream with this destination selected: you see the exact record, tabs and all, that the collector receives.