Skip to content
Avanet

Configure Sophos Central dashboards for operations

Central Overview is the default Sophos Central landing page. It shows current alerts, Account Health, users and devices, and license-dependent product information. Administrators can assemble custom dashboards from widgets for different responsibilities.

A dashboard is an overview, not proof of healthy operations. Filters, licensing, or delayed data can make widgets incomplete. Every metric therefore needs a defined drill-down and an owner.

Understand Central Overview first

The path is Dashboards > Central Overview. Typical areas include:

  • current alerts,
  • Account Health Check,
  • a summary of protected and unprotected users or devices,
  • product-dependent widgets for Email, Endpoint, or other services.

An informational alert does not automatically require action. A green health score does not cover every security control. And user or device count is not identical to contractual license usage.

Plan a custom operations dashboard

Define the dashboard’s question before adding widgets. Useful personal views include:

  • Daily Operations for new alerts, device problems, and health deviations,
  • Security Review for threats, isolations, and recurring causes,
  • Management Review for trends, protection coverage, and open risks,
  • License and Lifecycle for usage, inactive devices, and expiration.

A single dashboard containing every available widget quickly becomes unreadable. The daily landing page should contain only metrics that lead to an actual action.

Create a dashboard

The path is Dashboards > Manage dashboards > Create new.

  1. Enter a unique name and describe the purpose, then select Next to start designing.
  2. Scroll through the widget library on the left, filter by product or category, and check the sort order.
  3. Drag a widget onto the grid on the right or add it with the plus icon.
  4. Verify the filter, data source, and time range of every widget instance. The same widget can appear more than once with different settings.
  5. Place the most important warnings at the top left. Central initially places new widgets in rows from the top left; they can then be moved and resized from the lower corner.
  6. Finish with Done. Central returns to Manage dashboards; select the new dashboard name to open the finished view.

Central saves changes automatically during creation. The number on a widget in the library shows how many times it is used in the current dashboard. This allows the same metric to be shown separately for servers and endpoints without one instance replacing the other.

To edit it later, go to Dashboards > Manage dashboards and select the edit icon in the relevant row. Adjust the name, description, widgets, layout, size, and filters through the same workflow, then finish with Done. The Dashboard menu shows pinned views; unpinned dashboards remain accessible through Manage dashboards.

Custom Dashboards are personal. Other administrators do not see them automatically. A dashboard therefore replaces neither a shared monitoring platform nor a documented team handover.

Work with the widget library and grid

When creating or editing a dashboard, expand Widgets. The number beside the title shows all available widgets and, separately, newly added ones; a blue dot marks a new widget. Selection depends on licenses and administrator role, although Firewall Management widgets can remain visible without a firewall license.

When Sophos publishes additional widgets, they appear automatically in the library. Existing dashboards do not need to be recreated. The blue dot and count of new widgets provide a prompt for the next operational review.

Filters narrows the library by data source or Product, such as Endpoint or XDR, and by Category, such as Alerts or Threats. Sort by offers Newest, alphabetical Ascending, and Descending.

Either drag a widget onto the grid or add it with the plus icon that appears on hover. Central automatically arranges new widgets in rows from the top left. The same widget can be inserted multiple times and configured with a different data source or time range for each instance, for example All Alerts separated by product.

To resize a widget, move to the lower-left corner until the double arrow appears and drag it. A widget cannot be enlarged past a grid boundary. Other widgets move automatically where their size permits. The cross at the top right removes an instance, after which Central rearranges the grid.

If Sophos withdraws a widget or a Custom Role loses product access through None, a placeholder widget remains in its position and explains why. A later role expansion may add more widgets to the library. Investigate a missing widget against license, role, and product access instead of simply recreating it.

If an existing widget shows no data, first expand the time range and widget filters. Then check Data Lake uploads, device health, third-party integration, and the network connection to Sophos. An empty grid element proves neither that there were zero events nor that the dashboard is faulty.

After designing, Done exits the editor and returns to Manage dashboards. Select the dashboard name there to open the view and verify data, filters, and layout in normal viewing mode.

Role and license boundaries

Central Admins and Super Admins can manage dashboards. Enterprise Super Admins cannot always do this from a customer context. Available Sophos dashboards and widgets also depend on active licenses. A Threat Analysis Center dashboard, for example, requires XDR.

Firewall Management widgets are an exception. They remain visible in the widget library even without an active firewall license. Their presence alone proves neither that a firewall is licensed nor that useful data exists. Operational acceptance must verify that the expected firewalls are registered and the widget supplies current values.

If a widget is missing, first check the license, administrator role, and product access. A Custom Role can restrict access to the underlying product or sensitive reports.

Default, pinning, and lifecycle

Central Admins and Super Admins manage their personal dashboard list under Dashboards > Manage dashboards. Enterprise Super Admins cannot perform this management from every customer context.

Under Dashboards > Manage dashboards, the list identifies the creator: a Sophos badge marks supplied dashboards, while Custom Dashboards show the administrator who created them. Selecting the dashboard name opens the view. Find dashboards shows license-dependent Sophos dashboards. The plus icon in the right column adds a view to the personal list. It appears under Manage dashboards after the selection window is closed.

For the documented release, Sophos Help listed only the Threat Analysis Center dashboard under Find dashboards, visible with an XDR license. This is not a permanent count. Current operations should rely on the license-dependent selection actually shown in the tenant.

Sophos dashboards can be removed from the personal list with the minus icon and added again later through Find dashboards; Central Overview cannot be removed. Custom dashboards are permanently deleted with the cross and cannot be recovered. Before deletion, create a copy with Clone in the relevant row. Enter a name and description in the dialog, confirm with Clone, and then adjust its widgets.

Set default determines the view shown after sign-in. Pin shows or hides a dashboard in the Dashboard menu; new dashboards are pinned by default. The current default dashboard cannot be deleted or removed. Set another dashboard as default first.

At least quarterly, verify that widgets remain available, filters are correct, and the view reflects current operating objectives. Remove outdated project and trial dashboards.

Interpret PDF exports correctly

Sophos and Custom Dashboards can be exported as a PDF snapshot, except Central Overview. Open the dashboard from Manage dashboards and select the download icon at the top right. The file is saved in the normal download folder and contains the dashboard name, description, header, footer, and widgets in their visible arrangement.

Map-based widgets such as Sensor location of detection are not exported and leave an empty area. If such a component is necessary on screen, place it at the bottom right where possible for a cleaner PDF. Depending on configuration, partners can add branding and other information when exporting a customer dashboard. Before sharing, verify the generated PDF contains the correct customer and no unintended confidential information.

A PDF documents the visible moment, but not all raw data or subsequent changes. For incident response and audit, also preserve the underlying reports or logs.

  1. Open new and escalated alerts instead of merely counting them.
  2. Break health deviations down by affected products and devices.
  3. Investigate the real causes behind unprotected and deployment counts.
  4. Assign recurring problems to an owner and due date.
  5. After remediation, verify changes in the Audit Log and device view.

Detailed handling of the tenant-wide score is covered in Use Sophos Central Account Health Check correctly. Track administrative changes with Analyze and retain Sophos Central Audit Logs.

Do not repurpose a personal dashboard for recurring analysis and email distribution. Use Schedule, export, and monitor Sophos Central reports instead.

Common problems

Other administrators cannot see the dashboard

Custom Dashboards are user-specific by design. Document and recreate the configuration or use external reporting for a shared view.

A widget is missing or has no data

Check the license, product access, time range, and widget filters. Then open the underlying report directly. An empty widget does not automatically mean there are no problems.

The dashboard cannot be deleted

It may be the default or a Sophos-supplied dashboard. First select another default. Sophos dashboards are removed from the list, not deleted.

The PDF contains empty areas

Map-based widgets are not supported. Place them at the bottom right where possible or supplement the export with a separate report.

Frequently asked questions

Are Custom Dashboards visible to all administrators?

No. They belong to the administrator who created them. A shared operations view must be documented, recreated, or implemented in an external system.

Can Central Overview be exported as PDF?

No. Other Sophos and Custom Dashboards can be exported, although map widgets may remain empty in the PDF.

Does a green dashboard replace the daily review?

No. Filters, delays, and license boundaries can affect metrics. Critical values must be followed through to the underlying alert, report, or device.