Schedule, export, and monitor Sophos Central reports
Sophos Central provides different logs and reports depending on license and product. A report becomes operationally useful only when its time range, filters, recipients, ownership, and retention are defined. A saved view without an owner becomes unreliable after an administrator change or schedule expiration.
Distinguish logs, reports, and dashboards
| Area | Purpose |
|---|---|
| Log | Investigate individual events or administrative actions |
| Report | Save, export, or distribute filtered data as a repeatable analysis |
| Dashboard | Observe current state and trends as a working view |
A PDF report replaces neither raw data for an investigation nor a long-term SIEM archive. For administrative changes, the Sophos Central Audit Log remains the correct source.
Logs available under Reports
Entries visible under Reports depend on the license, enabled products, and administrator role. Central combines several technically different data sources there:
| Log | Content and responsibility |
|---|---|
| Events | Events from managed devices; operational analysis belongs in the relevant Endpoint or Server runbook. |
| Malware and PUAs blocked | Simplified Event Log extract for detected and blocked malware and potentially unwanted applications. |
| Audit Logs | Administrative Central activities; visibility and export depend on the role. |
| Data Loss Prevention | Events triggered by DLP rules on computers or servers. |
| Message History | Messages processed by Sophos Email for protected mailboxes. |
Do not merge these logs into one security indicator. An empty DLP or Message History area can result from a missing license, product, role, or filter and does not prove that no events occurred.
Recognize legacy and newer reports
In the saved reports list, Central identifies entries that use the older legacy format. This distinction matters because different limits apply.
The saved list shows report name, creator, format, and scheduled frequency. The Report Templates and Actively Scheduled bars do not count legacy reports. A chart count therefore does not prove that no older schedules remain; always review the complete list during handover. Most general logs and reports still use the legacy format.
For each administrator, legacy reports have these limits:
- no more than 25 scheduled and 25 unscheduled reports,
- up to 10,000 events per report or log,
- normally visible only to the creator,
- automatic end of email delivery after six months.
Partner and Enterprise administrators cannot simply take over these personal legacy reports in a customer tenant. If the creator leaves, recreate required reports under an appropriate operational administrator account before offboarding.
Newer report formats have different characteristics. Currently, each administrator can schedule up to 100 reports in this format. Authorized administrators, partners, and Enterprise administrators can view them. The newer format is not automatically available for every product and is used, among other areas, for MDR and Central Firewall. Rely on the format label shown in the portal, not the report name.
After six months, open, edit, and save a still-required legacy report again. This restarts the delivery period. Document the action with an owner and next review date rather than silently extending the report indefinitely.
Plan the report around a business question
Before saving, define purpose and scope:
- Which operational question should the report answer?
- Which products, groups, devices, and time ranges belong in it?
- Who assesses the result and by when?
- Does the output contain personal or security-sensitive data?
- Is a snapshot, recurring report, or SIEM data stream required?
A clear name contains the function, scope, and frequency, for example Endpoint Health - Produktion - wöchentlich. Names such as Test, Report 2, or a person’s name make later handover difficult.
The operational path begins under Reports. Depending on the report, limit the time range with From and To. Category tiles filter visible results, such as Active in the Computers report; other views support group filters and searches for specific values. Validate the result count after every filter change before saving or exporting the view.
Print opens a printer-friendly view. The browser dialog follows with Ctrl+P, or Cmd+P on macOS. Create a reusable report with Save as Custom Report: enter a name, select the required Frequency, and confirm with Save.
Save and distribute
Depending on the report, a print view, CSV, and PDF may be available. Not every report supports every option. CSV is suitable for filtering and correlation; PDF provides a readable snapshot.
When saving a Custom Report, send either a link or an attachment. For personal information, prefer a link because the recipient must authenticate to Central and the file is not retained in multiple mailboxes. Send attachments only to defined recipients and do not forward them through open distribution lists.
Scheduled email goes to the administrator who created the report. If ownership changes, save or reschedule it under the intended operational account. Silent forwarding from a personal mailbox is not a reliable ownership transfer.
Legacy reports can be scheduled weekly or monthly. Monthly delivery requires a selected period of at least 30 days. Fully test filters and the time range before saving; if they cannot later be changed as required, create a new report and remove the old one in a controlled manner.
Report language follows the Central administrator account that configured delivery. With partner access, the customer tenant language may be decisive. Do not mistake an unexpected language for a defective template.
Use co-branding correctly
Under Global Settings > Platform > Co-branding, a Super Admin or Admin can upload a company logo. It appears in the Self Service Portal and supported Endpoint and Server PDF reports. A partner logo can be inherited when the partner opened the customer tenant from Partner Portal.
When both partner and customer logos exist, the partner logo appears at the top right and the customer logo at the top left of the report. Before external delivery, generate a sample PDF and verify the tenant, branding, and confidential content.
To change to another logo or return to the Sophos logo, remove the existing logo first and then save the new selection. Co-branding changes neither report content nor permissions and is not a security feature. It only helps users recognize an official corporate portal or intended report.
Operations and handover
A monthly control run reviews:
- last successful delivery and next execution,
- business owner and valid recipients,
- report format and its limits,
- license and role changes,
- data volume and the possible 10,000-event limit,
- expiration date for legacy reports,
- necessity and retention of exports.
During administrator offboarding, review personal legacy reports, dashboards, API credentials, and alert rules together. Deleting the administrator must not silently interrupt monitoring or compliance evidence.