How to interpret Sophos Firewall User & Device Insights
Control Center > User & device insights is a triage view, not a single alarm state. Its tiles use different data sources and time ranges. A red endpoint, a high User Threat Quotient (UTQ), a TLS error, and a high session count may be related, but they do not have to be.
Use this safe sequence: record the affected tile and time range, open its details, correlate the user/IP/hostname and timestamp with logs and the firewall rule that actually matched, and only then change a policy or exception. Before any change, preserve a screenshot or export, filters, error count, target, owner, and expected result.
What each signal proves—and what it does not
- Security Heartbeat reports the health state sent by Sophos-managed endpoints. It does not prove that every connection from that device was blocked, or that a green device is free of every threat.
- Synchronized Application Control shows applications reported by managed devices. An entry proves detection, not policy enforcement or malicious activity.
- Zero-day protection counts analyzed files and findings. A scan count does not prove that every download was visible or harmful.
- UTQ prioritizes notable user accounts based on the previous seven days of browsing. It is an investigation lead, not proof of guilt or compromise.
- SSL/TLS connections describes observed connections and selected decryption-related errors. Percentages do not establish the protection applied to an individual flow.
- Firewall sessions shows active connections and proximity to capacity. A large count alone proves neither an attack nor overload.
Always seek at least two matching pieces of evidence, such as a tile and a detail log, or an endpoint event and Firewall Rule ID. For individual active flows, use Live Connections and Connection List.
Check Security Heartbeat and applications
Security Heartbeat has four states:
- At risk (red): active malware was detected.
- Missing (red): the endpoint is generating traffic but is not sending health information.
- Warning (yellow): inactive malware was detected, or malware was detected and cleaned up.
- Connected (green): no malware was detected and the endpoint reports healthy.
The tile counts every state. Clicking it, however, only lists red and yellow endpoints, including hostname, IP address, user, and time since the status changed. If all connected devices are green, the detail view is empty. This is neither a data fault nor a complete inventory.
If an endpoint leaves the network while its heartbeat is Missing, that state remains in Control Center and reports. It only changes when the endpoint reconnects. Before clearing a confirmed stale entry, record the endpoint name, age of the state, last known user and timestamp, and its current appearance in Control Center and the report. Complete the root-cause review first, then open the CLI and select 4. Device Console. You can remove all Missing entries at or beyond a specified age from 1 to 90 days, or one exact endpoint name:
system synchronized-security missing-endpoints delete days-missing 7
system synchronized-security missing-endpoints delete name endpoint1
7 and endpoint1 are examples; replace them with the approved age or exact name. The age command affects every entry that has been Missing for that many days or longer and may remove more devices than intended from Control Center and reports; the name command is narrower for one known retired device. Deletion neither repairs the endpoint nor Heartbeat and does not restore the removed history. Afterwards, reload Control Center and the affected report, confirm that only the intended entries disappeared, and, for a device still in service, verify reconnection and its new Heartbeat state.
For a red or yellow entry, first check the timestamp and endpoint in Sophos Fusion (formerly Sophos Central). Then confirm whether the matching firewall rule contains a Heartbeat condition at all. Visibility by itself does not enforce a block. Connecting Sophos Firewall to Sophos Fusion explains registration, prerequisites, and enforcement; use Missing Heartbeat alerts for persistent missing states.
The Synchronized Application Control tile shows New, Categorized, and the total number of discovered applications. Clicking it opens Applications > Synchronized Application Control. Assess a new application by device, user, and detection time, categorize it, and only then control it with an appropriate Application Filter. Direct database cleanup is not a triage step. For collection or storage failures, follow the safe database troubleshooting workflow. Policy assignment is covered in Application Control setup and testing.
Interpret zero-day counters and UTQ
The Zero-day tile requires an active Zero-Day Protection subscription. Under Administration > Licensing, the module must show Subscribed or Evaluating; without a subscription, the Control Center link can start a free 30-day evaluation.
The zero-day tile uses different windows:
- Recent: new reports for malicious, suspicious, or PUA files during the past seven days.
- Incidents: all files marked malicious, suspicious, or PUA; incident reports are retained for up to six months. Configure this under Report settings > Data management.
- Scanned: all traffic seen by Zero-day Protection, including clean files; its range depends on database-entry retention.
The SFOS 22 help explicitly states that the Zero-day Protection counters cannot be reset. The available SFOS 23 help omits this note; that omission does not establish reset support. Reset ‘Failed’ count applies only to the separate SSL/TLS failure counter, not to Zero-day Protection. Preserve counter readings and logs for investigation: restarting, deleting data, changing retention, or using a CLI reset are not recommended ways to reset these counters, including on SFOS 23.
Do not subtract these counters from each other. Open Zero-day protection > Downloads and attachments from the tile, then correlate file, verdict, user/IP, timestamp, and the affected web or mail path. Missing detections can also reflect licensing, policy, undecrypted traffic, or retention. See the Zero-day Protection operations guide.
UTQ evaluates browsing over the past seven days. It either reports no risky users or the number of users accounting for 80 percent of network risk. Click through to Reports > Dashboards for users and threat scores. Check categories, destinations, timestamps, and identity quality. Shared accounts, NAT, or missing authentication can distort attribution; a high score does not automatically justify blocking a user.
Analyze SSL/TLS connections safely
The tile updates decryption details every five minutes. If Control Center and Log Viewer show no connection or decryption data, confirm SSL/TLS inspection under Rules and policies > SSL/TLS inspection rules, then confirm the engine is Enabled under SSL/TLS inspection settings > Advanced settings > SSL/TLS engine.
- Of traffic is encrypted SSL/TLS traffic as a percentage of total firewall traffic.
- Decrypted is decrypted connections as a percentage of all SSL/TLS connections.
- Failed is the number of failed SSL/TLS connections. It resets automatically at midnight and can be reset manually with Reset ‘Failed’ count.
A manual reset cannot be undone, and the previous count cannot be restored. Record the value, time, and active test first. After resetting, repeat the same flow, wait at least one update cycle, and inspect detail logs. Resetting does not fix the cause.
The drill-down shows sessions from the past 24 hours and errors from the past 7 days. Both session and error data exclude connections through the web proxy. Top websites and Top users or IP addresses narrow the issue; clicking an error count opens filtered logs with the target in Server name. The list only includes errors that may be resolved through an SSL/TLS inspection rule or that indicate missing CA/application trust on the client. Web-policy and other security-policy blocks are not included.
Under Fix errors, websites, users, or IPs can be hidden from the error list. Hide changes the view only, not decryption. Show hidden and Unhide reverse it. Still record the filter so a hidden entry is not mistaken for a fixed error.
Exclude from decryption is a security change. Add domain or Add subdomain adds the destination to the Local TLS exclusion list URL group, editable under Web > URL groups. First capture the exact FQDN, affected clients, error ID, owner, expiry date, and positive/negative tests. Prefer the narrower subdomain when only one host is affected. Then verify that the application works, that this flow is no longer decrypted, and that other domains still follow the intended TLS rule. See the staged TLS inspection guide.
For rollback, remove only the exact entry you added—and only after confirming ownership and current use. Repeat the same test and watch for new trust or TLS errors. Never delete a shared or pre-existing exclusion as an assumed rollback.
Firewall sessions and decryption capacity
The session graph offers Live, 24h, 48h, Week, Month, and Year. Live updates every 30 seconds; all other ranges update every five minutes. Categories are Other traffic, Undecrypted SSL/TLS, and Decrypted SSL/TLS.
Decryption peak is the maximum concurrent decrypted connection count in the selected period and appears only when traffic is close to or above that level. Decryption limit is the maximum connections the specific appliance can decrypt and also appears only when traffic approaches it. An absent line does not mean unlimited capacity. A brief peak alone does not establish overload: compare ranges and recurring patterns with latency, resources, drops, and user errors.
Validate and roll back changes
- Preserve the baseline value, time range, filters, user/IP/hostname, error ID, and affected Rule ID.
- Test one hypothesis with the narrowest possible change.
- Repeat the same positive test; for an exclusion, also run a negative test outside its scope.
- Respect the tile’s update interval and compare detailed logs, not percentages alone.
- If there is no improvement, revert the change and recheck the data source, time range, web-proxy path, authentication, and rule match.
Hide/Unhide is fully reversible. Roll back a newly created TLS exclusion by removing that exact entry if nobody else uses it. A manually reset Failed count cannot be restored; the pre-change record is the only reliable historical reference.