Snare
From ITS Wiki - Information Technology Services - University of Rhode Island
Contents |
Windows Instructions
Installation
- Contact ITS Security with the following information:
- Name of server administrator
- Department
- Physical location of server
- Server IP address
- Operating system version
- Contact phone number and email address for server administrator.
- Install the Snare onto the target server.
- Note: You must have administrative privileges.
- Download the SnareSetup.exe to your desktop.
- Double click SnareSetup.exe.
- Click Next.
- Select the target install folder and click Next.
- Select Normal Installation from the components list and click Next.
- Select the target start menu location and click Next.
- Verify the selection options and click Install.
- After the program installs itself, it will attempt to start itself.
- When a dialog box appears, prompting you to specify whether to allow Snare to control the EventLog configuration, select Yes.
- Configure SNARE
- Enter the local host name; the IP address or DNS name of the local host
- If your server only has 1 interface, this can be left blank
- Enter the Snare server IP Address or DNS name
- Note: Alan White will provide this information
- Make sure the following options are selected:
- Enable syslog header
- Automatically set audit configuration
- Automatically set file system audit configuration.
- Click OK to close the dialog box and save configurations.
- Click File > Exit
- This will stop and restart the Snare service to pick up configuration changes.
- Enter the local host name; the IP address or DNS name of the local host
Removal
- Goto Start > Control Panel > Add/Remove Programs
- Select Snare
- Click Change/Remove
- Confirm the removal, click Yes.
- When the uninstaller has finsihed, click OK.
Linux/Unix Instructions
- Make sure sysklogd is installed
- Edit the /etc/syslog.conf file, add a line, *.debug @xxx.xxx.xxx.xxx (where xxx.xxx.xxx.xxx is the Snare server IP Address)
- Note: Alan White will provide this information
- Restart your sysklog service
Downloads
