SymtrexLogo
Knowledge is your Best Security
|
|
|
|

 

"In the IT security field, you fight knowledge with knowledge"

Robert Hocking, 2005
Symtrex CTO

 

 

Event Log Management
SNARE

The SNARE System is a comprehensive event monitoring and analysis tool designed for an organizations auditing requirements.  SNARE is comprised of two toolsets, the SNARE Agents and the SNARE Server.  The SNARE Agents are small programs that are installed on the host devices and allow you to define the security relevant events that you need to collect. Agents are currently available for Windows, Linux, Solaris, Irix, AIX, and MS SQL, with two additional Agents refered to as Epilog Agents for Windows and Linux.  While the agents are predominantly known due to the fact that they are available as Open Source, Enterprise SNARE Agents are available and provide additional functions which are required to satisfy most regulatory requirements.

The SNARE Server which is the central collector, receives the information from the Agents and from remote syslog (routers, switches and firewalls), and deposits the information into a datastore, allowing one to run reports, again based on their requirements. 

One of the key values is the Servers ability to define complex security objectives in an easy-to-program language, and report its findings in a simple manner. The Server itself comes equipped with a range of common security goals and objectives which can be cloned or copied to suit your corporations’ security objective.

While the SNARE System can track and monitor most standard requirements such as logins/logoffs, password expiration, it can also track:

  • Unauthorized access to the computer systems;
  • Unauthorized access to sensitive files;
  • Unauthorized use of account privileges;
  • Monitoring users access to the internet;
  • and more.

The SNARE Server, combined with the SNARE agents, is used by many organizations to meet some of the local and federal security requirements, such as : PCI DSS, NERC,  ACSI 33, GLBA (Gramm-Leach-Bliley Act), Sarbanes Oxley (SOX), DCID 6/3, Nispom Chapter 8, HIPAA.

SNARE is as a base model that allows collection of up to 250 devices (remote syslog and open sourced agents). Depending on your requirement Enterprise SNARE Agents can be purchased for more reliability and integrity of the data. It is available as either software only (ISO) or as an applianced product.


To view a demo of the server, http://demo.intersectalliance.com - the username of Snare_Admin and password of Welcome-2-Snare.  To book a comprehensive web demonstration with one of our SE’s please contact us.

For more information, please visit our dedicated web site - www.snare-server.com