Skip to content
Avanet

Schedule, export, and monitor Sophos Fusion reports

Sophos Fusion provides different logs and reports depending on license and product. A report becomes operationally useful only when its time range, filters, delivery method, ownership, and retention are defined. A saved view without an owner becomes unreliable after an administrator change or schedule expiration.

Quick path for legacy reports: Under Reports, open the required report, set the time range and filters, and validate the results. For a one-time output, select Export to CSV, Export to PDF, or Print. For a schedule, open Save as Custom Report, select the delivery method, Frequency, and format, and confirm with Save. Report settings can’t be changed after creation, so verify the time range and filters first.

Distinguish logs, reports, and dashboards

AreaPurpose
LogInvestigate individual events or administrative actions
ReportSave, export, or distribute filtered data as a repeatable analysis
DashboardObserve current state and trends as a working view

A PDF report replaces neither raw data for an investigation nor a long-term SIEM archive. For administrative changes, the Sophos Fusion Audit Log remains the correct source.

Logs available under Reports

Entries visible under Reports depend on the license, enabled products, and administrator role. Sophos Fusion combines several technically different data sources there:

LogContent and responsibility
EventsEvents from managed devices; operational analysis belongs in the relevant Endpoint or Server runbook.
Malware and PUAs blockedSimplified Event Log extract for detected and blocked malware and potentially unwanted applications.
Audit LogsAdministrative Sophos Fusion activities; visibility and export depend on the role.
Data Loss PreventionEvents triggered by DLP rules on computers or servers.
Message HistoryMessages processed by Sophos Email for protected mailboxes.

Do not merge these logs into one security indicator. An empty DLP or Message History area can result from a missing license, product, role, or filter and does not prove that no events occurred.

Recognize legacy and newer reports

In the saved reports list, Sophos Fusion identifies entries that use the older legacy format. This distinction matters because different limits apply.

The saved list shows report name, creator, format, and scheduled frequency. The Report Templates and Actively Scheduled bars do not count legacy reports. A chart count therefore does not prove that no older schedules remain; always review the complete list during handover. Most general logs and reports still use the legacy format.

For each administrator, legacy reports have these limits:

  • no more than 25 scheduled and 25 unscheduled reports,
  • up to 10,000 events per report or log,
  • normally visible only to the creator,
  • automatic end of email delivery after six months.

Partner and Enterprise administrators cannot simply take over these personal legacy reports in a customer tenant. If the creator leaves, recreate required reports under an appropriate operational administrator account before offboarding.

Newer report formats have different characteristics. Currently, each administrator can schedule up to 100 reports in this format. Authorized administrators, partners, and Enterprise administrators can view them. The newer format is not automatically available for every product and is used, among other areas, for MDR and Central Firewall. Rely on the format label shown in the portal, not the report name.

After six months, open, edit, and save a still-required legacy report again. This restarts the delivery period. Document the action with an owner and next review date rather than silently extending the report indefinitely.

Plan the report around a business question

Before saving, define purpose and scope:

  1. Which operational question should the report answer?
  2. Which products, groups, devices, and time ranges belong in it?
  3. Who assesses the result and by when?
  4. Does the output contain personal or security-sensitive data?
  5. Is a snapshot, recurring report, or SIEM data stream required?

A clear name contains the function, scope, and frequency, for example Endpoint Health - Production - weekly. Names such as Test, Report 2, or a person’s name make later handover difficult.

The operational path begins under Reports. Depending on the report, limit the time range with From and To. Category tiles filter visible results, such as Active in the Computers report; other views support group filters and searches for specific values. Not every report offers every filter or output option. Validate the result count after every filter change before saving or exporting the view.

For a one-time output, the following options are available depending on the report:

  • Print opens a printer-friendly view. Then open the browser’s print dialog with Ctrl+P, or Cmd+P on macOS.
  • Export to CSV exports the currently filtered view as a CSV file for further filtering and correlation.
  • Export to PDF exports the current view as a readable snapshot.

Save and email a legacy report

The following workflow applies to general Custom Reports in the legacy format. Newer reports, such as those for MDR or Central Firewall, have their own characteristics. Follow the format label and actions shown in the portal.

  1. Under Reports, open the required report and fully configure its time range and filters. You can’t change these settings after creating the Custom Report. Create a new report if its scope must change later.
  2. Select Save as Custom Report and enter a clear Name in the Save Report dialog.
  3. For email delivery, select Send a link to the report or Attach the report to the email. Sophos recommends the link for personally identifiable information. Opening it requires Sophos Fusion sign-in credentials and avoids placing another report file in the mailbox.
  4. Under Frequency, select weekly or monthly. Monthly is only available when the report’s previously selected time range covers at least 30 days.
  5. Select PDF or CSV as the output format and finish with Save.

The scheduled email is received by the administrator who created the report. The dialog doesn’t describe a freely configurable recipient list. If ownership changes, recreate the report under the intended operational account. Silent forwarding from a personal mailbox is not a reliable ownership transfer.

After saving, check the entry in the list at the top of the Reports page. Its name, creator, format, and scheduled frequency must match the operating record. For an email schedule, also verify actual delivery to the creator’s mailbox. This validates both the stored configuration and the delivery path.

Report language follows the Sophos Fusion administrator account that configured delivery. With partner access, the customer tenant language may be decisive. Do not mistake an unexpected language for a defective template.

Use co-branding correctly

Under Global Settings > Platform > Co-branding, a Super Admin or Admin can upload a company logo. It appears in the Self Service Portal and supported Endpoint and Server PDF reports. A partner logo can be inherited when the partner opened the customer tenant from Partner Portal.

For the complete setup, including file selection, preview, partner inheritance, and rollback, see Sophos Fusion co-branding.

When both partner and customer logos exist, the partner logo appears at the top right and the customer logo at the top left of the report. Before external delivery, generate a sample PDF and verify the tenant, branding, and confidential content.

To change to another logo or return to the Sophos logo, remove the existing logo first and then save the new selection. Co-branding changes neither report content nor permissions and is not a security feature. It only helps users recognize an official corporate portal or intended report.

Operations and handover

A monthly control run reviews:

  • expected delivery interval and actual receipt by the creator,
  • business owner and associated administrator account,
  • report format and its limits,
  • license and role changes,
  • data volume and the possible 10,000-event limit,
  • expiration date for legacy reports,
  • necessity and retention of exports.

During administrator offboarding, review personal legacy reports, dashboards, API credentials, and alert rules together. Deleting the administrator must not silently interrupt monitoring or compliance evidence.

Troubleshoot common failures

Monthly isn’t available: The report’s selected time range must cover at least 30 days. Correct the range, validate the results again, and then create the Custom Report.

The saved report has the wrong filters or time range: These settings can’t be changed after creation. Create a replacement with the correct scope and only remove the old entry after validating the replacement.

Another administrator can’t see the report: Check the format label first. Legacy reports are visible only to their creator. Partner and Enterprise administrators also can’t see or create them in the customer tenant.

The bars show fewer schedules than expected: Report Templates and Actively Scheduled exclude legacy reports. Use the complete saved-report list for the control.

A scheduled legacy report no longer sends: If it was set up about six months ago, open, edit, and save it again. Then verify receipt in the creator’s mailbox. If delivery still fails, check that the expected report remains in the portal, that the administrator account is valid, and that its mailbox accepts mail. Don’t infer an absence of events from an empty mailbox.

Frequently asked questions

Why did scheduled reports suddenly stop arriving?

Legacy reports stop emailing after six months. Edit and save the report again, then verify receipt by the administrator who created it.

Can an Enterprise administrator see every report in a sub-estate?

Not generally. Personal legacy reports are visible only to their creator. Newer report formats can be visible to authorized partner and Enterprise administrators.