Snare Reflector — Log Routing & SIEM Optimisation

Your logs. Your rules. Any destination.

Snare Reflector is a high-performance, policy-driven log routing engine that sits between your log sources and SIEM platforms. Filter, transform, and route log streams to multiple destinations simultaneously, reducing SIEM ingest costs, eliminating vendor lock-in, and preserving full architectural flexibility.

It receives log streams, applies configurable filtering, format transformation, and schema remapping rules, then routes events simultaneously to multiple destinations — SIEMs, data lakes, message brokers, and archives — with load balancing, failover, and real-time monitoring.

Multi-destination routing | TLS/mTLS transport| Policy-based filtering | Format transformation

How It Works

Real-time log orchestration from ingest to destination

Snare Reflector operates as an active broker in the log pipeline, processing every event through a configurable policy engine before delivering to one or many destinations simultaneously.

01 // INGEST

Multi-Protocol Ingestion

Receives log streams from Snare Agents, syslog sources, Snare Central, or any standard log emitter via TCP, UDP, TLS, syslog RFC 3164/5424, or Snare native protocol. High-throughput, multi-threaded ingestion with no event loss.

TCP/TLS/UDP
syslog RFC 3164/5424
02 // POLICY

Policy-Based Routing & Filtering

Each incoming event is evaluated against routing rules — by source, log type, event ID, severity, metadata, keyword, or regex. Rules determine which events go to which destinations. Low-value events are dropped or redirected before reaching high-cost ingestion platforms.

rule engine
no regex required
03 // TRANSFORM

Format Transformation

Events are transformed to the format required by each destination — JSON, CEF, LEEF, Syslog, or custom templates. Field remapping aligns data to Splunk CIM or Sentinel ASIM schemas automatically, reducing engineering effort for normalisation.

CEF/LEEF/JSON
schema mapping
04 // DELIVER

Simultaneous Multi-Destination Delivery

Events are delivered to all configured destinations simultaneously — with independent delivery queues, failover logic, and load balancing per destination. If a destination is unavailable, events are queued for guaranteed delivery on recovery.

multi-destination
failover

Technical Specifications

Enterprise-grade routing infrastructure

Ingestion

//Protocols in – Syslog (RFC 3164, RFC 5424), TCP, TLS, UDP, Snare native protocol

//Sources  – Snare Agents, syslog emitters, Snare Central, network devices, any standard log source

//Throughput – Multi-threaded engine — enterprise-scale EPS (events per second)

//Buffering  – In-memory and disk-based queue — no event loss during destination outages

//Compression – Compressed ingestion and forwarding supported

//Authentication – mTLS for inbound and outbound connections

Routing & Filtering

//Rule engine – Policy rules by source, log type, severity, keyword, metadata field, regex

//UI routing  – Dropdown filters by system and log type — no regex required for common cases

//Destinations – Multiple simultaneous destinations per routing policy

//Custom names  – Per-destination custom naming for operational clarity

//Load balancing – Round-robin and weighted load balancing across destination clusters

//Failover – Automatic failover to secondary destinations on primary failure

Delivery Protocols & Destinations

//Splunk – HEC (HTTP/HTTPS), syslog

//Microsoft Sentinel – HTTPS to Azure Log Analytics

//IBM QRadar – LEEF format syslog

//Securonix – Native Securonix syslog format

//Devo – Syslog ELB with mTLS (cert + chain upload)

//Generic – Any syslog destination, Kafka, Amazon S3, Azure Blob, HEC-compatible

Transformation, Enrichment & Monitoring

//Output formats – JSON, CEF, LEEF, Syslog (RFC 3164/5424), custom templates

//Schema mapping – Splunk CIM, Sentinel ASIM templates; custom field remapping

//Enrichment – Custom log tagging and metadata addition per routing rule

//Truncation – Field truncation rules to reduce payload size before ingestion

//Deduplication – Configurable event deduplication to reduce volume

//Monitoring – Real-time throughput dashboard, per-destination health, volume metrics

Key Capabilities

The intelligent data broker for your security pipeline

Eliminate SIEM Vendor Lock-In

Snare Reflector decouples log collection architecture from SIEM vendor selection. Route the same log stream to multiple SIEMs, switch vendors without rebuilding collection, or run parallel platforms during migrations — with no endpoint changes required.

// Lock-in elimination
– Same collection, any SIEM
– Parallel SIEM operation
– Migration without re-engineering
– Vendor evaluation risk-free

SIEM Ingest Cost Reduction

Apply filtering and truncation rules upstream of every ingestion-priced destination. Remove high-volume noise events, drop duplicate log lines, truncate verbose fields, and redirect cold data to cheaper storage — before a single event is counted for billing.

// Cost reduction levers
– Event-type filtering rules
– Field-level truncation
– Deduplication engine
– Cold-data redirect to S3/Blob

Multi-SIEM & Hybrid Environments

Route to Splunk in one region and Sentinel in another simultaneously. Feed the same security events to both a production SOC SIEM and a compliance archive. Power multi-cloud and hybrid architectures with a single routing layer — no duplicate agents.

// Multi-SIEM routing
– Per-destination filter rules
– Region-aware routing
– SOC + compliance split
– Independent delivery queues

TLS & mTLS Security

All inbound and outbound connections support TLS 1.2/1.3 and mutual TLS (mTLS) with certificate and chain upload. Devo integration supports Syslog ELB with mTLS. Ensures log data is encrypted and authenticated throughout the routing pipeline.

// Security controls
– TLS 1.2 / TLS 1.3
– mTLS (cert + chain upload)
– Per-destination cert config
– Snare Central RBAC integration

Real-Time Monitoring Dashboard

Built-in dashboards show per-destination throughput, event rates, queue depth, connection status, and error rates in real time. Identify bottlenecks, track delivery health, and maintain SLA visibility across all routing flows from a single pane of glass.

// Monitoring metrics
– EPS per source and destination
– Queue depth and backlog
– Connection status per dest

Resilience & High Availability

Multi-threaded engine with load balancing across destination clusters. Automatic failover to secondary destinations on primary failure. Disk-based event queuing ensures zero event loss during destination outages or SIEM maintenance windows.

// HA architecture
– Multi-threaded forwarding
– Auto-failover to secondary
– Disk-backed delivery queue

USE CASES

Built for the complexity of real enterprise security architectures

CISO / SecOps Engineering

SIEM Migration Without Coverage Gaps

A global enterprise is migrating from Splunk to Microsoft Sentinel across a 12-month programme. Snare Reflector routes the full log stream to both SIEMs simultaneously throughout the migration — enabling parallel operation, validation of Sentinel detection coverage, and a clean cutover with no data gaps.

Outcome

Migration completed without coverage gaps. Both SIEMs validated in parallel. Cutover executed cleanly with zero endpoint changes.

MSSP

Multi-Tenant SIEM Delivery from Single Collection

An MSSP collects logs from 60 customer environments using Snare Agents. Snare Reflector routes each customer’s log stream to their specific SIEM destination — some to Splunk, others to Sentinel, others to QRadar — with per-customer filter policies applied at the routing layer.

Outcome

60 customer SIEM destinations served from single collection layer. Per-customer filter policies enforced centrally. SIEM migration for individual customers handled without agent changes.

Security SI

Designing Cost-Optimal Log Architecture for Enterprise Client

A security SI is designing a log architecture for a large enterprise with multiple SIEM platforms, a compliance archive requirement, and a need to reduce existing Splunk ingest costs. Snare Reflector provides the routing layer that sends filtered security events to Splunk, routes compliance events to Snare Central, and directs verbose app logs to S3 — from one agent estate.

Outcome

Splunk ingest reduced 55%. Compliance archive established at 90% lower cost. Architecture fully documented and handed over.

SOC Engineering

Reducing Alert Noise Before SIEM Ingest

A SOC was experiencing significant analyst fatigue from noisy, repetitive events (scheduled task completions, verbose IIS access logs, low-severity Windows events) polluting SIEM dashboards. Snare Reflector applied pre-ingest filter rules to suppress these event classes before they reached the SIEM — reducing daily ingest volume and alert noise simultaneously.

Outcome

Daily SIEM ingest volume reduced 48%. Alert noise reduced by equivalent proportion. Analyst triage time per shift decreased measurably.

Route every log to exactly where it needs to go

Snare Reflector gives your security architecture the routing intelligence and SIEM flexibility that direct-forwarding tools simply can’t provide.

FREQUENTLY ASKED QUESTIONS

Questions from security architects and SOC engineers

Q: What is Snare Reflector and how does it differ from a standard log forwarder?

Snare Reflector is a policy-driven log routing and optimisation engine, not a simple forwarder. Unlike basic log forwarders, Reflector applies configurable filtering, format transformation, schema remapping, and multi-destination routing to every event, with load balancing, failover, real-time monitoring, and mTLS security. It is designed for enterprise-grade log pipeline orchestration, not point-to-point forwarding

Q: How does Snare Reflector eliminate SIEM vendor lock-in?

Snare Reflector decouples log collection architecture from SIEM vendor selection. Because Reflector handles routing independently from collection, organisations can run parallel SIEMs during migrations, switch vendors without rebuilding collection infrastructure, or feed the same log stream to multiple platforms simultaneously — all without changing any agent configuration on any endpoint.

Q: How does Event Replay to Microsoft Sentinel work?

Event Replay allows archived logs stored in the Snare Central compressed archive to be replayed on demand directly into a Microsoft Sentinel workspace or Splunk. The team selects a time range and log types, Snare Central delivers with the appropriate schema mapping (ASIM for Sentinel, CIM for Splunk) applied, and the data appears in the SIEM for investigation. When the investigation is complete, replay stops — no permanent retention expansion and no additional ongoing ingestion cost.

Q: Can Snare Reflector route to multiple SIEMs simultaneously?

Yes. Snare Reflector supports simultaneous delivery to multiple destinations — each with independent filter rules, format settings, delivery protocol, and delivery queue. A single log stream can be routed to Splunk for the SOC, Sentinel for a regional team, and S3 for cold archive at the same time. Delivery to each destination is fully independent, so a failure at one destination does not affect delivery to others.

Q: What happens to events if a destination SIEM goes offline?

Snare Reflector maintains a disk-backed delivery queue per destination. If a destination becomes unavailable, events are queued locally and delivered in sequence when the destination recovers. Queue depth and backlog are visible in the real-time monitoring dashboard. This ensures zero event loss during SIEM maintenance windows or unexpected outages — a critical requirement for environments with strict log completeness obligations

Q: What security protocols does Snare Reflector support?

All inbound and outbound connections support TLS 1.2 and TLS 1.3. Mutual TLS (mTLS) is supported for destinations requiring certificate-based authentication — including Devo Syslog ELB. Certificate and certificate chain upload is available per destination in the configuration interface. All transport is encrypted by default.

Q: How does the routing policy UI work — do I need to know regex?

No. Snare Reflector’s routing UI provides dropdown filters for routing by system identifier and log type, covering the vast majority of standard routing use cases without requiring regex knowledge. Custom destination names provide immediate operational context. For advanced users requiring more granular routing control, regex-based rules remain fully available alongside the dropdown interface.

Snare Solutions
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.