Skip to content
Avanet

Schedule Sophos Firewall reports and send them by email

Sophos Firewall can send local reports as a PDF every day or every week. To ensure recipients receive a useful analysis rather than just any file, first check the report manually and only then schedule it.

The reliable process is short:

  1. Generate the required report manually with the intended time range and filter.
  2. Save the selection as a bookmark if necessary.
  3. Create a schedule under Reports > Show report settings > Report scheduling.
  4. Use Send test mail to test the mail path.
  5. Use Generate now to generate and send the report immediately.
  6. Check the received PDF for content, time range, language, and sensitive data.

Send test mail and Generate now do not test the same thing: the test email confirms the mail transport. Only Generate now also verifies that the firewall can generate the selected report and send it as a PDF.

⚠️ The XGS 87/87w and XGS 88/88w models don’t support on-appliance reporting. For these models or for central analysis across several firewalls, use Sophos Central Firewall Reporting.

Check the prerequisites

Clarify five fundamentals before creating the schedule:

  • Local reports work: Under Reports, the required time range already contains plausible data. A schedule can’t fix missing logging or an empty report database.
  • Email delivery works: The mail server, authentication, TLS, sender, and recipient are configured under Administration > Notification settings. The complete process is described in Configure and test Sophos Firewall email notifications.
  • Time and time zone are correct: An incorrect system time makes it difficult to select and verify the report period. Configure date, time, and NTP explains the setup.
  • Local storage is available: On-box report data is stored under /var. When the stop threshold is reached, the firewall suspends reporting. Check Sophos Firewall storage and manage reports explains status, warning thresholds, and retention.
  • Recipient and purpose are defined: A functional mailbox such as firewall-reports@example.net is usually better than a personal address. It needs an owner who actually reviews the reports.

A PDF can contain users, IP addresses, MAC addresses, email addresses, URLs, and security events. Keep the recipient group small, encrypt the mail transport, and consider retention in the mailbox. If Data Anonymization for logs and reports is used, verify in the PDF that was actually received that the expected data is anonymized.

Prepare the report content

In this example, a weekly IPS report should show which attacks were detected most frequently. Adapt the names and values to the local environment.

  1. Open Reports > Network & threats > Intrusion attacks.
  2. Select the required date range.
  3. Use Filter to restrict the analysis to relevant systems, rules, or events if necessary.
  4. Select Generate.
  5. Check whether the time range, hits, and sorting match the intended question.

The business purpose should be explainable in one sentence, for example: “Every Monday, the security team reviews the most frequent IPS hits from the previous week.” This statement helps determine which report, filter, and recipient are actually needed.

Save a recurring selection as a bookmark

A bookmark is useful when a reusable filtered selection should be scheduled instead of an entire report group.

  1. Open the fully prepared report.
  2. Select Bookmark.
  3. Enter a descriptive name such as Weekly-IPS-Review.
  4. Select a suitable bookmark group and save it.

If no suitable group exists, create one under Reports > Show report settings > Bookmark management > Add bookmark group. A name such as Weekly-IPS-Review describes the purpose and frequency better than Report1.

After saving, reopen the bookmark and generate the report again. This verifies that the intended selection is actually reused. Don’t infer the exact period covered by the later PDF from the name alone; verify it in the generated PDF.

Create the schedule

  1. Open Reports > Show report settings > Report scheduling.
  2. Select Add.
  3. Select Report as the type.
  4. Under To email address, enter the recipients. Separate multiple addresses with commas.
  5. Under Report type, select a report group or the prepared bookmark.
  6. If available, choose sorting by Hits or Bytes to suit the purpose.
  7. Under Email frequency, select Daily or Weekly.
  8. Save the schedule.

The example uses these values:

  • Recipient: firewall-reports@example.net
  • Report type: bookmark Weekly-IPS-Review
  • Sorting: Hits
  • Frequency: Weekly

These values aren’t a general standard. Sorting by Bytes may be more useful for a bandwidth report, an operational report may need Daily, and another site may require a separate recipient or bookmark.

Scheduled on-box reports are sent as PDFs and contain no more than 50 records. This limit applies to the emailed report; it must not be treated as a complete archive or export of all local data. For several firewalls, consolidated HA data, or longer central analyses, Sophos Central Firewall Reporting is the more appropriate layer.

Since SFOS 21.5 MR1, a scheduled PDF report uses the WebAdmin language of the administrator who created the schedule. If the recipient should receive the report in German, create the schedule from a German WebAdmin session and verify the result with Generate now.

In addition to standard reports, report scheduling also offers Security audit report and, when the integration is configured, ConnectWise. The Security Audit Report is intended in particular for passive Discover Mode analysis with TAP and SPAN. These types serve different purposes and should not be selected merely because a standard report is empty.

Check delivery and the PDF

Don’t wait until the first regular execution after saving the schedule.

1. Test mail transport with Send test mail

Select the schedule in the list and run Send test mail. Then check the destination mailbox, spam filter, or mail-server tracking to confirm that the message was accepted and delivered.

A successful test email confirms SMTP, authentication, and basic delivery. It doesn’t confirm that the selected report contains data or can be generated as a valid PDF.

2. Test the complete path with Generate now

Then run Generate now. The firewall immediately generates the scheduled report and sends it to the configured recipients.

Check the received PDF for:

  • the correct firewall or site;
  • the intended report group or bookmark selection;
  • a plausible time range and timestamps;
  • useful sorting and amount of data;
  • the expected language;
  • readable tables and charts;
  • no unnecessary disclosure of user, network, or security data.

Only then observe the next regular run. The current help doesn’t describe the exact relationship between execution time, time zone, and report period in enough detail to assume it universally. The generated report is therefore the proof that the process works.

Operation in an HA cluster

Local report data isn’t synchronized between the HA nodes. Both nodes process data for the traffic that passes through them. If a node’s report contains data, that node can send the scheduled message. As a result, an HA cluster may deliver two emails for the same schedule.

This delivery isn’t automatically an error. First compare the sender, appliance identity, period, and content of both PDFs. For a consolidated view across both nodes, Central Reporting is more appropriate than two local email reports.

After an HA failover, appliance replacement, or firmware update, test Generate now again. This reveals if a schedule is still visible but its data, language, or mail delivery no longer meets expectations.

Troubleshoot systematically

Send test mail fails

The problem is then in the mail path, not yet in the report content. Under Administration > Notification settings, check DNS, route, port, authentication, OAuth, TLS, certificate, sender, and recipient. Mail-server tracking or quarantine shows whether the message was accepted or rejected.

Don’t recreate the schedule several times. A test email must first arrive reliably. The error patterns and safe checks are described in email notifications.

The test email arrives, but Generate now doesn’t deliver a report

The SMTP path is now basically confirmed. Check the following next:

  1. Is the correct report group or bookmark selected in the schedule?
  2. Does the same report contain data when generated manually?
  3. Is on-box reporting enabled and supported by the appliance model?
  4. Is /var below the report stop threshold?
  5. Are logging and the required protection functions enabled for the expected data?
  6. Does the message appear in mail-server tracking, spam, or quarantine?

Two read-only commands in the Device Console show the current on-box status and report storage thresholds:

show on-box-reports
show report-disk-usage watermark

The commands don’t change anything. Further storage diagnostics and the meaning of the output are described in Manage storage and reports.

The PDF is empty, incomplete, or displayed incorrectly

First generate the same report manually with the identical time range and filter. If the WebAdmin report is already empty, report data, logging, or matching events are missing. If only the PDF contains incorrect or incomplete data, document the SFOS version, build, browser, schedule, Generate now time, and a sample PDF.

SFOS 22.0 MR2 Build 546 fixes, among other issues, an empty daily traffic dashboard PDF without on-box reporting and incorrectly displayed tables or charts in on-demand PDFs generated in Chrome. A similar symptom on another build isn’t automatically the same issue. Check the exact build and compare it with a manually generated report before making changes.

For a deeper analysis, correlate the test time with cschelper.log, reportdb.log, garner.log, and, if necessary, postgres.log. Access is described in Sophos Firewall Troubleshooting: Services and Logs. A single log entry isn’t sufficient reason to restart reporting services or delete report data.

The Executive Report with 1 month can’t be downloaded as a PDF

For SFOS 22.0 MR1 Build 490, Sophos documents a narrowly scoped issue under NC-182976: Under Reports > Dashboards > Executive report, the PDF download can fail when 1 month is selected as the time range. First check the exact firmware build, report type, time range, and output format. Other PDF reports or scheduled email reports aren’t automatically affected.

In the description, Sophos mentions a CSV download with a one-day time range, but the separate KIL column Workaround still states None. This export is therefore only a limited fallback check. It doesn’t replace a complete monthly report and confirms neither the monthly report nor the PDF generation path. If other reports, time ranges, or formats also fail, the issue is broader than NC-182976; document the time and browser and collect the logs listed above instead of restarting reporting services or deleting report data.

The current Known Issues list only shows SFOS 23.0 EAP0 Build 253 in the Fix versions field and additionally announces a fix for SFOS 22.0 MR3 in the description. As of August 10, 2026, MR3 hasn’t been released and therefore isn’t an available solution. If the same symptom occurs on MR2 or another build, don’t automatically attribute it to NC-182976; investigate it using the collected data.

The email contains only 50 entries

This is the documented upper limit for scheduled email reports. Choose filters and the report purpose so that the most important 50 records answer the specific operational question. If complete raw data, a longer history, or analyses across several firewalls are required, a central reporting or SIEM workflow is more appropriate.

The same report arrives twice

In an HA cluster, both nodes can send a message if their local report contains data. Compare the sender, appliance, and content before deleting an apparently duplicate schedule. On a standalone firewall, check whether two schedules use the same report selection and recipient.