Analysing Sophos Endpoint events, alerts and reports
Sophos Central shows the same environment from different perspectives. Events are the technical history, Alerts group activity that may require action, Audit Logs record administrative changes and Reports summarise devices, protection or specialised functions.
An Alert can be closed or automatically resolved while the underlying Event remains. Conversely, an Event may only become an Alert later, for example when an Endpoint has not complied with policy for two hours.
Events
Under Reports > General Logs > Events, events can be searched by user, device or threat name and filtered by category. File names are currently not a search field. The period extends up to 90 days.
The Event table shows Severity, time, type, user, user group, device and device group. A saved Custom Report view is visible only to the administrator who created it. Partner or Enterprise administrators do not automatically see this personal view.
Exports provide the current view or up to 90 days as CSV or PDF. For recurring evaluations, record which filters were active; otherwise, two exports are difficult to compare.
Alerts
Under My Environment > Alerts, open, closed, reopened and resolved Alerts are displayed. Multiple Events can be grouped into one Alert. Filters are available for Severity, product, category, available action, title and period.
Acknowledge removes an Alert from the active list but does not resolve a threat or clean up the local Quarantine Manager. Mark as Resolved likewise only confirms that the cause has already been addressed; on Windows, this action removes threat details from the local Quarantine Manager.
An application false positive is not authorised from the Alert list but through the specific Event. A PUA authorisation from Alerts, however, applies tenant-wide to all computers and therefore has a wider scope than a policy exclusion.
Important time limits
| Activity | Threshold or retention |
|---|---|
| Policy non-compliance | Alert after two hours |
| Real-time protection disabled | High Alert after 2.5 hours |
| protection setup failed | High Alert after one hour |
| Restart pending | Alert after two weeks |
| Outbreak | 100 Detections in 24 hours |
| Events and Audit Log | up to 90 days |
| deleted devices and Tamper Protection passwords | 120 days, recovery for 30 days |
These limits explain why a change does not appear immediately in the same view. The absence of an Alert shortly after a policy deviation is not yet proof of correct compliance.
Audit Log
Under Reports > General Logs > Audit Logs, Sophos shows seven days by default and up to 90 days. It records the administrator, object type, change, description and source IP address.
The current View export applies date and search filters. An export of the previous 90 days applies only the search filter, not the date range selected on screen. For incident documentation, choose the export option deliberately.
Live Response sessions appear in the Audit Log. The detailed Session Audit also contains the commands entered and is downloaded separately as a compressed file.
DLP Event Log
The Endpoint DLP log is available under Reports > Endpoint & Server Protection Logs > Data Loss Prevention. It shows the rule, action, file name and destination. An Endpoint sends no more than 50 DLP Events per hour to Central; additional events remain local. An export contains no more than 5,000 Events.
The Data Control Summary Report under Sophos Email belongs to a different product and must not be used to evaluate Endpoint DLP.
Computer and Hero Report
The Computer Report shows managed Endpoints with their last status, last user, update time, group and Agent Status. “Online” or Last Active is updated only about once an hour on average.
The Hero Report summarises 30 days of blocked threats, protected assets, Web Control impact and licence usage. The period cannot be changed, the Report covers only one tenant and cannot be scheduled. It is suitable for a management overview, not as a complete incident record.
Dashboards and widgets
The Central Overview Dashboard combines the most important Alert, Health, device, user and Web Control information. Additional Sophos Dashboards depend on the available licences. The Threat Analysis Center Dashboard, for example, requires XDR.
Central Admins and Super Admins can create and clone their own Dashboards under Dashboards > Manage dashboards, set them as the default and pin them to the menu. These Custom Dashboards are personal: other administrators do not see them automatically. A Dashboard is therefore not a shared operational definition unless its filters, widget selection and responsibilities are also documented.
Widgets can be used more than once with different filters. If a widget is missing or shows no data, first check the licence, role, data source, time range and filters. An empty widget does not prove that no Events exist.
Sophos and Custom Dashboards can be exported as PDF snapshots, but the Central Overview Dashboard cannot. Map-based widgets appear empty in the PDF. For auditable evaluations, CSV or API exports and documented filters remain more important than a visual Dashboard snapshot.
Attack Details
When Sophos detects a serious ongoing attack, a banner appears that cannot simply be dismissed. The Attack Details Report shows affected devices and a timeline. New Events are added for up to 30 days or until the administrator confirms that the attack has been resolved.
Closing the banner does not automatically close the associated critical Alert. Check both states separately. This feature is available to Endpoint or XDR customers with suitable administrator permissions, but not in the same form to MDR customers.
Operational schedule
Review High Alerts, unremediated threats, Outbreaks and failed installations daily. Weekly checks cover Policy Compliance, update and Restart Events, and recurring PUAs. Monthly reviews cover the Audit Log, Hero Report, licence display and long-term device hygiene.
A Report does not replace a response. Every metric should have an owner, threshold and defined next step.
Related articles
The technical handling of threats is covered in Sophos Endpoint threat cleanup and malware remediation. Configure Sophos Endpoint Data Loss Prevention explains DLP-specific events.