We use Snare for picking up Windows logs, and we used to use it for SQL as well. We had used it for Linux once or twice. We're mainly using it for Windows and Windows flat files.
Snare provides scalable log management solutions tailored for enterprises seeking efficient security and compliance. It collects logs from diverse environments, enabling real-time monitoring and response.


| Product | Mindshare (%) |
|---|---|
| Snare | 1.0% |
| Splunk Enterprise Security | 6.8% |
| Wazuh | 4.8% |
| Other | 87.4% |
Snare offers flexible pricing tailored to various business needs. Cost structures include a one-time licensing fee or subscription model, often depending on the number of log sources or volume of data ingested. Pricing may vary based on the selected tier, features, and support level, providing options for both small enterprises and large organizations requiring extensive monitoring capabilities.
Snare is designed to facilitate seamless integration of log data to aid in security intelligence and policy adherence. It's versatile in capturing logs across platforms, offering organizations the ability to centralize monitoring efforts. With its robust analytics framework, businesses can detect anomalies and ensure regulatory compliance more effectively.
What are Snare’s most important features?In finance, Snare helps meet compliance standards by providing comprehensive audit trails. Retail sectors use it for detecting fraud while maintaining data integrity. Technology companies leverage its scalability to monitor expansive infrastructures effectively.
Military, Defence and Security Agencies, Banking Finance and Insurance companies, Retail, Health and Utilities.
| Author info | Rating | Review Summary |
|---|---|---|
| Information Security Engineer at Glasshouse Systems | 4.0 | I use Snare primarily for Windows log collection due to its flexibility in filtering unnecessary data. However, its GUI needs modernization and GPO support is cumbersome. I switched from IBM AL as it was being deprecated. |
| Senior Cyber Security Analyst at Securonix | 4.0 | I need Snare to ingest data into our SIEM solution where we can map and configure rules. Snare's format is consistently reliable, though identifying event types and installation can initially be challenging. No other solutions were previously considered. |
| Engineer at Jupiter Technology | 4.0 | Snare features effective agents, particularly for Windows, handling various log types like file integrity monitoring and USB events. However, the SIEM-like feature on Snare Central Server is under development and not yet complete. |

We use Snare for picking up Windows logs, and we used to use it for SQL as well. We had used it for Linux once or twice. We're mainly using it for Windows and Windows flat files.
The most valuable feature of Snare is flexibility or the ability to filter all things you don't want and don't have security value.
Snare should modernize its GUI a little bit. The solution's GPO support is kludgy and could be more straightforward.
I have been using Snare for seven to eight years.
Years back, when they did upgrades, the solution failed to remove the previous one and install the new one completely. However, the newer versions have not had that problem.
I rate Snare a nine out of ten for stability.
The solution is deployed on 2,000 machines, and four users use it in our organization.
I rate Snare ten out of ten for scalability.
Our experience with the solution's technical support was good. I rate Snare's technical support a four or five out of ten.
Neutral
I previously used IBM AL. I switched to Snare because IBM AL was being deprecated.
Snare’s initial setup is super easy. I rate Snare an eight out of ten for the ease of its initial setup.
We implemented Snare through an in-house team. The solution’s deployment takes a couple of weeks.
Snare is competing with solutions like Splunk, LogRhythm, QRadar, and WinCollect, and those are free. Snare has a pretty reasonable cost. Years back, the solution cost $10 to $15 a node. The SQL agent is not cheap.
On a scale from one to ten, where one is cheap, and ten is expensive, I rate Snare's pricing a four out of ten.
Snare is a great product that is easy to roll out and manage.
Overall, I rate Snare an eight out of ten.

We need Snare to ingest the data into our SIEM solution. We do the mappings, and then we configure the rules on top of the data we receive from Snare.
The best thing about Snare is its format and consistency. There are different standards of logs, but Snare's format is consistent from the beginning and doesn't change.
Users will initially find it difficult to identify the event types and installation in Snare.
I have been using Snare for three years.
The solution's basic functions work smoothly, but some complex functions take some time to load on GUI.
The solution has good scalability. I work with more than 600 customers, and most of them are using the Snare solution.
The solution's initial setup is very easy and just takes some clicks.
Snare is a cheap solution because a lot of customers are using it.
We are an MSSP, and we have different customers. I'm not working on Snare directly, but I'm working on the actual data. We collect the data and create the rules on top of the data and Snare events. I am happy with the solution's GUI. I would recommend Snare to other users because it is better for sending data, installing, and forwarding the data.
Users will initially find it difficult to identify the event types and installation, but it gets easier as you use it. Snare is a well-known format, and most SIEM solutions are utilizing it. So, it's very easy to configure on their end as well. Snare sends data into a specific format, including security data and non-security data.
Overall, I rate the solution an eight out of ten.
Snare has good agents, especially for Windows. It can correct a lot of different types of logs from agents, especially file integrity monitoring and USB events.
The solution is now developing a SIEM-like feature on Snare Central Server, but it's not complete yet.
I have been using Snare for about half a year.
Snare is a stable solution.
Snare is a scalable solution.
Snare's technical support is very good because they provide 24/7 support.
Positive
Snare is easy to deploy, and its deployment takes about a day.
Snare has reasonable pricing.
I recommend Snare as a good solution for medium and large-sized companies.
Overall, I rate Snare an eight out of ten.