QRadar: Snare hostname in syslog header and log source name

How does QRadar determine the Log Source identifier of Snare events?


We look for an IP or Hostname in the syslog header. You can configure SNARE to insert the desired IP or Hostname with the following process:

  • Open SNARE for Windows, select network configuration and override detected DNS Name with: IP or Hostname.
  • This will be the value that Snare uses in the syslog header.

Modified date:
16 June 2018