Skip to content
Avanet

Analyze and retain Sophos Fusion Audit Logs

Sophos Fusion (formerly Sophos Central) records administrative activity in the Audit Log. After a false positive, policy change, or suspicious sign-in, it shows which account performed the action, at what time, and from which IP address.

The Audit Log is not a complete SIEM. The portal can display and export activity from the past 90 days. If you need a longer evidence period, you must secure exports outside Central in good time. The Audit Log page does not state that data is retained for longer or forwarded automatically.

Do not confuse Audit Log and Event Log

LogTypical question
Audit LogWho changed a role, policy, exclusion, or setting?
EventsWhat did a protected device or Sophos product report?
AlertsWhich assessed notification requires investigation or action?

Blocked malware appears as an event or alert. Closing that alert later, adding a global exclusion, or changing a role is instead an administrative activity in the Audit Log.

Sophos also states that the logs available in a tenant depend on its licence. If the entire log type is missing rather than one entry, check the licence first and then the administration role.

An audit entry may, for example, report that Users and Groups were changed, identify the newly created user as the specific object, or record a successful Central account authentication. The combination of object type, modified object, description, and acting account is more informative than any one field alone.

Access and roles

The current path is Reports > General logs > Audit Logs. Access depends on the administration role. However, the Audit Log page specifies neither a universal Custom Role field name nor one required role. Check the role actually assigned in your tenant rather than relying on a UI field that may not be shown.

Audit access should not be granted indiscriminately to every help-desk account. Entries contain administrator names, IP addresses, and security-relevant changes. At the same time, at least one operational role needs access so incidents can be investigated without relying exclusively on a Super Admin account.

Read the fields correctly

Each entry typically contains:

  • Date for date and time,
  • Modified by for the acting Central account,
  • Item type for the affected object class,
  • Item modified for the specific object,
  • Description for additional details,
  • IP address for the source address of the action.

Modified by provides little accountability when accounts are shared. This is one reason every person requires a separate administrator account. It lets you attribute a recorded change without inferring more than Sophos actually displays.

Investigate in the correct order

For a suspicious change, first narrow the relevant time range. Central shows the last seven days by default, and the portal range can be extended to at most 90 days. Select Update after changing the date or search term.

Search is deliberately limited. Sophos documents exactly two search types:

  • the IP address from which a change was made,
  • the value in Modified by.

Both search types are combined with the selected time range.

Without a search term, all activities in the selected range are shown. Without a date range, Central searches the last seven days by default. These two cases help reveal whether an apparent gap is simply caused by a filter left in place.

Then examine related changes as a sequence. A global exclusion may follow a sign-in, role change, policy adjustment, and alert closure. A single entry does not explain that context.

Use exports correctly

Central offers four export options. There is an important difference:

  • CSV of current view and PDF of current view apply all currently selected filters,
  • CSV of past 90 days and PDF of past 90 days export the past 90 days; only the search filter applies, not the selected date range.

Start the export from Export on the right of the Audit Logs page. Deliberately select the current view or 90-day export and the required format. Before clicking, reread the search term and view so a filtered file is not mistakenly stored as the complete audit record.

Immediately assign an unambiguous filename after export, for example including the tenant, time range, and creation date. Do not place generic names such as audit.csv unchanged in a shared folder.

CSV is suitable for filtering, correlation, and automated processing. PDF is useful when an unchanged snapshot is required for a ticket or approval. For evidence preservation, also record a hash of the exported file and store the original read-only.

Preserve exports without gaps

Sophos specifies a displayable and exportable period of no more than 90 days for Audit Logs, but does not prescribe an operational export schedule. Choose and monitor your own schedule so that the oldest unsecured entry does not leave this window. Deliberately overlapping periods protect against gaps after a failed run; check the period and contents after export.

This guide does not promise API-based ingestion as an alternative: the reviewed Audit Log documentation describes only manual CSV and PDF exports. Before automating, verify in the current API documentation for your tenant that Audit Log data is actually available.

A useful retention rule defines:

  • the responsible team and storage location,
  • retention duration according to internal and legal requirements,
  • access protection and immutability,
  • time synchronization,
  • search and restore testing,
  • the procedure for a failed export.

Important control cases

Do not wait for an incident before opening the Audit Log. Regular samples should specifically review:

  • successful sign-ins,
  • users and groups that were added, changed, or deleted.

Do not infer other monitored actions from a wish list. For an important control case, make a harmless test change, search the appropriate period with Update, and check it again after export. Only then add that result to your control procedure.

Common problems

Expected change is missing

First check the time range, search filter, and Update. Then remove the filter and reload the same range. If the activity is still absent, establish whether it is among the activities monitored by Sophos Fusion; the documentation does not promise that every conceivable product action is recorded.

Export contains more data than the view

For past 90 days, the date range selected in the portal does not apply as it does for current view. For tightly scoped evidence, export the current view and then verify its contents.

Times do not match other logs

First establish the time zone and daylight-saving rules of the comparison sources. Then correlate by Modified by, IP address, and a narrow time range. The audit entry itself shows a date and time, but the reviewed Sophos page documents no additional time-zone column.

Audit access is missing

Because access depends on the administration role, have an authorised administrator review the role assignment. Do not search for a supposedly universal checkbox name: the reviewed Audit Log page does not specify one.

Frequently asked questions

How long are Audit Logs available in the Central portal?

Activities can be displayed and exported for at most 90 days in the portal. For longer retention, secure exports outside Central in good time. The product page reviewed here does not promise an Audit Log API.

Does the Audit Log also show malware detections?

Not as the primary source. Malware detections belong to Events and Alerts. The Audit Log shows administrative actions around those detections, such as creating an exclusion or closing an alert.

Is PDF better than CSV?

PDF is suitable as a readable snapshot. CSV is better for search, correlation, and SIEM ingestion. Investigations often retain both formats.