Skip to content
Avanet

Schedule Sophos Firewall reports and send them by email

Sophos Firewall can send local reports as a PDF every day or every week. To ensure recipients receive a useful analysis rather than just any file, first check the report manually and only then schedule it.

The reliable process is short:

  1. Generate the required report manually with the intended time range and filter.
  2. Save the selection as a bookmark if necessary.
  3. Create a schedule under Reports > Show report settings > Report scheduling.
  4. Use Send test mail to test the mail path.
  5. Use Generate now to generate and send the report immediately.
  6. Check the received PDF for content, time range, language, and sensitive data.

Send test mail and Generate now do not test the same thing: the test email confirms the mail transport. Only Generate now also verifies that the firewall can generate the selected report and send it as a PDF.

⚠️ The XGS 87/87w and XGS 88/88w models don’t support on-appliance reporting. For these models or for central analysis across several firewalls, use Sophos Central Firewall Reporting in Sophos Fusion.

Check the prerequisites

Clarify six fundamentals before creating the schedule:

  • Local reports work: Under Reports, the required time range already contains plausible data. A schedule can’t fix missing logging or an empty report database.
  • Email delivery works: The built-in or external mail server and its required authentication, connection security, sender, and recipient settings are configured under Administration > Notification settings. The complete process is described in Configure and test Sophos Firewall email notifications.
  • Time and time zone are correct: An incorrect system time makes it difficult to select and verify the report period. Configure date, time, and NTP explains the setup.
  • Local storage is available: On-box report data is stored under /var. When the stop threshold is reached, the firewall suspends reporting. Check Sophos Firewall storage and manage reports explains status, warning thresholds, and retention.
  • Local retention meets the purpose: Under Reports > Show report settings > Data management, you can retain reports for no more than one year. The selected period counts backward from the previous month, and a change takes effect at 00:00. This setting only applies to reports, not to logs or PDF files already delivered to a mailbox. The firewall automatically deletes older reports. Before changing the retention period, therefore, check the organization’s compliance and retention requirements.
  • Recipient and purpose are defined: A functional mailbox such as firewall-reports@example.net is usually better than a personal address. It needs an owner who actually reviews the reports.

A PDF can contain users, IP addresses, MAC addresses, email addresses, URLs, and security events. Keep the recipient group small, encrypt the mail transport, and consider retention in the mailbox. If Data Anonymization for logs and reports is used, verify in the PDF that was actually received that the expected data is anonymized.

Control Top Users in PDF Reports Globally

The vaguely named Device Console command system custom-feature controls whether generated PDF reports also include Top Users. The switch is system-wide and has no report or recipient parameter. Because the current SFOS 22 help does not state a default, read the existing state first:

system custom-feature show

Use enable to add Top Users and disable to remove them from generated PDFs again:

system custom-feature enable
system custom-feature disable

Before enable, review recipients, retention, and Data Anonymization. Then use Generate now to produce a real PDF and confirm that the expected users appear and sensitive identities are protected as intended. The switch does not create missing user attribution and does not repair an authentication or logging problem. Rollback uses disable and is confirmed with show and a newly generated PDF.

Prepare the report content

In this example, a weekly IPS report should show which attacks were detected most frequently. Adapt the names and values to the local environment.

  1. Open Reports > Network & threats > Intrusion attacks.
  2. Select the required date range.
  3. Use Filter to restrict the analysis to relevant systems, rules, or events if necessary.
  4. Select Generate.
  5. Check whether the time range, hits, and sorting match the intended question.

The business purpose should be explainable in one sentence, for example: “Every Monday, the security team reviews the most frequent IPS hits from the previous week.” This statement helps determine which report, filter, and recipient are actually needed.

Distinguish custom report, custom view, and bookmark

A Custom report under Reports > Custom narrows a single data area using detailed criteria. Web, mail, FTP, user, and web server reports are available. The boundary for web reports is important: The custom search only shows allowed domains, URLs, categories, and IP addresses. Check blocked web access instead under Reports > Applications & web > Blocked web attempts.

A Custom view combines several report groups in one view, such as Zero-day protection activity and web users. Create it under Reports > Show report settings > Custom view > Add with a name and the required report groups; it then appears under Reports > Custom. Generate and review the new view manually before scheduling or sharing it.

A Bookmark, by contrast, stores an already filtered recurring selection. A schedule can select a default or custom report group or a bookmark. The best choice for an administrator is not the technically largest report, but the smallest selection that answers the specific operational question.

Save a recurring selection as a bookmark

A bookmark is useful when a reusable filtered selection should be scheduled instead of an entire report group.

  1. Open the fully prepared report.
  2. Select Bookmark.
  3. Enter a descriptive name such as Weekly-IPS-Review.
  4. Select a suitable bookmark group and save it.

If no suitable group exists, create one under Reports > Show report settings > Bookmark management > Add bookmark group. A name such as Weekly-IPS-Review describes the purpose and frequency better than Report1.

After saving, reopen the bookmark and generate the report again. This verifies that the intended selection is actually reused. Don’t infer the exact period covered by the later PDF from the name alone; verify it in the generated PDF.

Create the schedule

  1. Open Reports > Show report settings > Report scheduling.
  2. Select Add.
  3. Select Report as the type.
  4. Under To email address, enter the recipients. Separate multiple addresses with commas.
  5. Under Report type, select a report group or the prepared bookmark.
  6. If available, choose sorting by Hits or Bytes to suit the purpose.
  7. Under Email frequency, select Daily or Weekly.
  8. Save the schedule.

The example uses these values:

  • Recipient: firewall-reports@example.net
  • Report type: bookmark Weekly-IPS-Review
  • Sorting: Hits
  • Frequency: Weekly

These values aren’t a general standard. Sorting by Bytes may be more useful for a bandwidth report, an operational report may need Daily, and another site may require a separate recipient or bookmark.

Scheduled on-box reports are sent as PDFs and contain no more than 50 records. This limit applies to the emailed report; it must not be treated as a complete archive or export of all local data. For several firewalls, consolidated HA data, or longer central analyses, Sophos Central Firewall Reporting in Sophos Fusion is the more appropriate layer.

Since SFOS 21.5 MR1, a scheduled PDF report uses the WebAdmin language of the administrator who created the schedule. If the recipient should receive the report in German, create the schedule from a German WebAdmin session and verify the result with Generate now.

In addition to standard reports, report scheduling also offers Security audit report and, when the integration is configured, ConnectWise. The Security Audit Report is intended in particular for passive Discover Mode analysis with TAP and SPAN. These types serve different purposes and should not be selected merely because a standard report is empty.

Configure Security audit and ConnectWise schedules deliberately

A Security audit report is a predefined report about security-related activity. Its schedule has the following fields: Organization name for the name shown in the report, To email address for comma-separated recipients, Report type for the report group or bookmark data, and Email frequency for Daily or Weekly delivery.

A ConnectWise schedule is available only after ConnectWise is integrated with Sophos Firewall. Configure its exact fields as follows:

  • Report: Select one of the preconfigured ConnectWise reports: Top sites, Filtered sites, Bandwidth usage, or Top attacks.
  • Number of records: Set how many records the report creates. Choose the count for the review purpose rather than assuming the general 50-record email limit is the desired ConnectWise value.
  • Frequency: Schedule the report daily at the specified interval.

After saving either specialized schedule, use Generate now and inspect the delivered report. An integration being enabled or a schedule appearing in the list doesn’t by itself prove that the predefined report contains the expected records.

Check delivery and the PDF

Don’t wait until the first regular execution after saving the schedule.

1. Test mail transport with Send test mail

Select the schedule in the list, run Send test mail, enter a test address, and select Send. You enter this address separately for the test; it doesn’t have to match the schedule’s To email address. Use the same functional mailbox for a meaningful first test. Then check that mailbox, the spam filter, or mail-server tracking to confirm that the message was accepted and delivered.

A successful test email confirms the configured mail-server connection and basic delivery. It doesn’t confirm that the selected report contains data or can be generated as a valid PDF.

2. Test the complete path with Generate now

Then run Generate now. The firewall immediately generates the scheduled report and sends it to the configured recipients.

Check the received PDF for:

  • the correct firewall or site;
  • the intended report group or bookmark selection;
  • a plausible time range and timestamps;
  • useful sorting and amount of data;
  • the expected language;
  • readable tables and charts;
  • no unnecessary disclosure of user, network, or security data.

⚠️ When upgrading from SFOS 20.0 or earlier to SFOS 21.0 or later, reports from before and after the upgrade are stored in separate databases. If only the migration day is selected, select Data before migration and Data after migration individually to analyze the entire day. A date range that includes the migration day must instead be split into ranges before and after that day. Rolling back to the earlier version loses all reports generated since the upgrade, even after upgrading again. Account for this database boundary when checking scheduled PDFs: successful email delivery alone does not prove uninterrupted coverage across the migration.

Check date attribution after an interruption: Some data may remain unprocessed at shutdown. After restarting, events in that data may be assigned to the day before the restart rather than their actual event day, even a day when the firewall was off. This concerns remaining unprocessed data, not all events indiscriminately. After an interruption, therefore, use Generate now to generate a new PDF and check its period and event dates carefully.

Only then observe the next regular run. The current help doesn’t describe the exact relationship between execution time, time zone, and report period in enough detail to assume it universally. The generated report is therefore the proof that the process works.

Operation in an HA cluster

Local report data isn’t synchronized between the HA nodes. Each node only contains reports for the traffic it processes. As soon as the report generated by either the primary or auxiliary node has at least one row of data in any table, both appliances send the report; if no table contains data, no report is sent. An HA cluster may therefore deliver two emails for the same schedule.

This delivery isn’t automatically an error. First compare the sender, appliance identity, period, and content of both PDFs. For a consolidated view across both nodes, Central Reporting is more appropriate than two local email reports.

After an HA failover, appliance replacement, or firmware update, test Generate now again. This reveals if a schedule is still visible but its data, language, or mail delivery no longer meets expectations.

Troubleshoot systematically

Send test mail fails

The problem is then in the mail path, not yet in the report content. Under Administration > Notification settings, check DNS, route, port, authentication, OAuth, TLS, certificate, sender, and recipient. Mail-server tracking or quarantine shows whether the message was accepted or rejected.

Don’t recreate the schedule several times. A test email must first arrive reliably. The error patterns and safe checks are described in email notifications.

The test email arrives, but Generate now doesn’t deliver a report

The SMTP path is now basically confirmed. Check the following next:

  1. Is the correct report group or bookmark selected in the schedule?
  2. Does the same report contain data when generated manually?
  3. Is on-box reporting enabled and supported by the appliance model?
  4. Is /var below the report stop threshold?
  5. Are logging and the required protection functions enabled for the expected data?
  6. Does the message appear in mail-server tracking, spam, or quarantine?

Two read-only commands in the Device Console show the current on-box status and report storage thresholds:

show on-box-reports
show report-disk-usage watermark

The commands don’t change anything. Further storage diagnostics and the meaning of the output are described in Manage storage and reports.

The PDF is empty, incomplete, or displayed incorrectly

First generate the same report manually with the identical time range and filter. If the WebAdmin report is already empty, report data, logging, or matching events are missing. If only the PDF contains incorrect or incomplete data, document the SFOS version, build, browser, schedule, Generate now time, and a sample PDF.

SFOS 22.0 MR2 Build 546 fixes, among other issues, an empty daily traffic dashboard PDF without on-box reporting and incorrectly displayed tables or charts in on-demand PDFs generated in Chrome. A similar symptom on another build isn’t automatically the same issue. Check the exact build and compare it with a manually generated report before making changes.

For a deeper analysis, correlate the test time with cschelper.log, reportdb.log, garner.log, and, if necessary, postgres.log. Access is described in Sophos Firewall Troubleshooting: Services and Logs. A single log entry isn’t sufficient reason to restart reporting services or delete report data.

The Executive Report with 1 month can’t be downloaded as a PDF

For SFOS 22.0 MR1 Build 490, Sophos documents a narrowly scoped issue under NC-182976: Under Reports > Dashboards > Executive report, the PDF download can fail when 1 month is selected as the time range. First check the exact firmware build, report type, time range, and output format. Other PDF reports or scheduled email reports aren’t automatically affected.

In the description, Sophos mentions a CSV download with a one-day time range, but the separate KIL column Workaround still states None. This export is therefore only a limited fallback check. It doesn’t replace a complete monthly report and confirms neither the monthly report nor the PDF generation path. If other reports, time ranges, or formats also fail, the issue is broader than NC-182976; document the time and browser and collect the logs listed above instead of restarting reporting services or deleting report data.

The current Known Issues list shows SFOS 23.0 EAP0 Build 275 in the Fix versions field and still describes the fixes for SFOS 23 and SFOS 22.0 MR3 as upcoming. Before upgrading, check the current release notes to confirm that a released target version is available and supported for the appliance model. If the same symptom occurs on MR2 or another build, don’t automatically attribute it to NC-182976; investigate it using the collected data.

The email contains only 50 entries

This is the documented upper limit for scheduled email reports. Choose filters and the report purpose so that the most important 50 records answer the specific operational question. If complete raw data, a longer history, or analyses across several firewalls are required, a central reporting or SIEM workflow is more appropriate.

The same report arrives twice

In an HA cluster, both appliances send the report when the report generated by either the primary or auxiliary appliance has at least one row of data in any table. Compare the sender, appliance, and content before deleting an apparently duplicate schedule. On a standalone firewall, check whether two schedules use the same report selection and recipient.