Skip to content
Avanet

Operate the Sophos NDR appliance and sensor safely

A Sophos NDR appliance can host two different workloads: the NDR sensor, which analyzes mirrored network traffic, and appliance-based third-party integrations, also called Log Collector integrations in Sophos Fusion. Operations therefore involve two interfaces:

  • Sophos Fusion is the central inventory and entry point. It shows appliances, assigned integrations, and high-level resource metrics, and provides central actions such as Collect logs, Remote Assistance, and Open Appliance Manager.
  • Sophos Appliance Manager runs on the appliance and shows the local status of the VM, NDR, and log collectors. Use it to restart specific components or perform a controlled restart or shutdown of the entire VM.

The safest rule is: Restart only the smallest component proven to be affected. Restarting NDR allows the log collectors to continue running; restarting an individual log collector leaves NDR and the other integrations unaffected. Restart or Shutdown of the VM, however, interrupts every workload on that appliance.

Scope: The local Restart and Shutdown steps in this runbook apply to the virtual appliance managed in Appliance Manager. They do not establish a power procedure for certified NDR hardware.

Quick selection: Which interface and which action?

TaskLocationImpact
Inventory the appliance and hosted integrationsFusion, My Products > NDR > Appliancesread-only
Check local status and versionAppliance Manager, Status, NDR, Integrations, Advancedread-only
Query local NDR events for diagnostic purposesAppliance Manager, NDR Queryread-only; predefined query against the local VM database
Restart only the NDR sensorAppliance Manager, NDR > Restart NDRNDR is interrupted; log collectors remain active
Restart one log collectorAppliance Manager, Integrations > Restartonly this integration is restarted
Restart all log collectorsAppliance Manager, Integrations > Restart Allall log collectors are restarted; NDR remains active
Request appliance logsFusion, appliance menu Collect logsdiagnostic request, not an operational restart
Restart the entire VMAppliance Manager, Actions > RestartNDR and all log collectors stop and are reset
Shut down the entire VMAppliance Manager, Actions > ShutdownNDR and all log collectors stop; a separate power-on is required

1. Inventory the appliance and workloads in Sophos Fusion

In My Products > NDR > Appliances, you are taken to the Integration Appliances tab for configured integrations. Alternatively, go directly to Threat Analysis Center > Integrations > Configured > Integration Appliances.

Before making any change, clearly identify the correct appliance and record the following details in the change record or support case:

  • Appliance name and Type
  • Network protocol and Syslog IP
  • number shown under Integrations
  • displayed values for CPU, Memory, Storage 1, and Storage 2
  • Log requested status
  • planned action, maintenance window, and responsible person

Expand the arrow next to the appliance name. This reveals the integrations actually hosted on it. For each entry, record in particular the Integration name, Vendor, Protocol, Port, Configuration Type, and Off/On setting. This step prevents a supposed standalone NDR sensor from being restarted when the same appliance is also processing syslog data from a third-party product.

Interpret Fusion statuses correctly

  • Waiting for deployment is the expected status for a newly created appliance that has not yet been deployed. Image creation may still be in progress.
  • Once image creation is complete and Download image is offered, the image is ready to download and deploy. This is not yet a runtime or connectivity test.
  • Connected is an intermediate milestone after deployment: the appliance has connected to central management. The status does not prove that packets are arriving on every SPAN port or that NDR data is being uploaded successfully.
  • Off/On belongs to the respective expanded integration and indicates whether that integration is active. It is not the same as the appliance’s connection status.
  • Log requested indicates whether a Collect logs request was sent for the appliance. It is not a health status.

The resource metrics in Fusion provide a fleet overview, not a complete local diagnosis. To assess a specific appliance, open Appliance Manager next.

2. Open Appliance Manager and capture a baseline

From the appliance’s three-dot menu, select Open Appliance Manager and confirm the dialog with Open. Appliance Manager opens in a new window.

The local account is named zadmin. For a newly created appliance, the password is displayed once when it is saved and must be stored securely. For an existing appliance or a forgotten password, you can set a new password via reset it in the opening dialog. If too many incorrect attempts have locked the account, the hypervisor web console provides an alternative: select Unlock Account in the Weblink interface. This requires pre-existing authorized hypervisor access; do not infer any shell, SSH, or console steps from it. Never put a password in a ticket or operations log.

Before intervening, capture the following baseline information from the Appliance Manager header:

  • Version
  • K3S Helm Chart version
  • Uptime
  • System ID

Then check the four operational tabs:

  1. Status shows local CPU and memory utilization, as well as root and data disk utilization.
  2. NDR shows the upload percentage, capture per configured SPAN port, and the network flow graph in 30-second intervals. SPAN port 2 appears only if a second port is configured.
  3. Integrations shows the status, last restart, and Received, Filtered, Accepted, and Uploaded counts for each log collector.
  4. Advanced shows the status and restart times of the containers in which the integrations run.

Record values with timestamps rather than merely noting “green” or “working.” A screenshot or the relevant values are usually sufficient for comparison after the intervention; complete exports are not required.

Check local events with NDR Query

NDR Query in Appliance Manager is a local diagnostic tool: it searches the NDR event database on this specific appliance VM. This database is not the Sophos Data Lake. NDR Query is also not the Investigation Console: the Investigation Console is a separately deployed threat-hunting console operated on the local network and assigned an NDR appliance.

For a supported diagnostic check in Appliance Manager:

  1. Record the incident time window, appliance name, and question to be answered.
  2. Open NDR Query and select Example queries on the Query page.
  3. In Example queries, find the predefined query that matches the question and select the Copy icon next to it.
  4. Paste the copied query into the text box and select the Go icon.
  5. Save the output under Query Results together with the time window. You can reorder the columns by drag-and-drop for analysis.

Appliance Manager currently provides only these predefined queries. Do not derive a custom SQL query or use a query from the Investigation Console here. Document an empty result as well; by itself, it proves neither missing SPAN traffic nor a failed Data Lake upload. Check these stages separately under NDR.

3. Change settings in a controlled manner

The Management Interface, Proxy, SYSLOG, and SPAN settings are under Actions > Settings. A change begins not with saving, but with a scope check:

  1. Can the discrepancy be confirmed locally in Appliance Manager and in Fusion?
  2. Does it affect the management connection, syslog ingestion, or NDR packet capture?
  3. Which NDR and log collector workloads share the appliance?
  4. Is the original value documented, and is there a rollback path?
  5. Does the specific setting require a VM restart?

Do not change management, proxy, or network settings speculatively. An incorrect management configuration can make Appliance Manager and the connection to Sophos Fusion unreachable. Changes to SYSLOG can affect third-party integrations; SPAN settings apply only to NDR. Before saving, therefore change only the affected area and do not test multiple fault hypotheses at the same time.

If the interface requires a restart for a change, do not trigger the restart immediately. First perform the prechecks described in the next section and use an appropriate maintenance window.

Deliberately authorize OS Detection in Global NDR Settings

When the appliance has an NDR integration, Global NDR Settings contains the VLAN Strip and OS Detection options. Both are turned off by default. OS Detection is not a passive sensor metric: when enabled, the appliance uses Nmap every two hours to scan every internal IP address that NDR has seen on the network and identify its operating system. These scans can trigger detections in other security products.

Before enabling it, document the purpose, affected internal networks, approval from the network and security owners, and the expected detection pattern. If scans against internal systems are not permitted or their effects in other tools cannot be monitored, leave OS Detection turned off.

For an approved activation:

  1. Document the initial OS Detection state, appliance, time, and expected internal test systems.
  2. Turn on OS Detection and change only this setting.
  3. For at least one complete two-hour interval, confirm that the setting remains active and whether the responsible security tools report expected or unexpected scan detections. Check NDR, upload, and log collector status in parallel.
  4. Assess the result with the responsible owners. Unexpected alerts, unauthorized target systems, or operational impact are stop criteria.

Rollback: Turn off OS Detection again and document the time. Then confirm that no new scan events caused by this feature appear; process alerts already generated in other tools according to their procedures. Do not reproduce the Nmap commands manually or add speculative exceptions on target systems.

Correct Management locally only for an offline VM

The local Actions > Settings > Management page is a recovery path only when the VM has no network connectivity. As long as connectivity exists, make management changes in Sophos Fusion. This runbook does not establish access to an offline VM where none already exists: the following steps apply only when the dashboard is reachable through an existing, approved recovery method. If no such access exists, escalate to the responsible platform owner or Sophos Support.

Before the change, record the current and intended values for IP Assignment, IPv4/Netmask, Gateway IP, DNS, DNS 2, and, if used, Enable Web Proxy, Web Proxy Type, Proxy URL, and Port Number. Handle the proxy Username and Password only in the password management system. Also inventory all hosted NDR and log collector workloads, because a confirmed change with a restart interrupts the entire appliance, not only the management interface.

Edit only the smallest necessary value: for a fixed address, select Edit under IPv4 configuration, set IP Assignment to Static, enter the address with its CIDR prefix as well as the gateway and DNS, and select Save. Configure a web proxy through Enable Web Proxy and the appropriate Web Proxy Type only when one is actually required. Before confirming, re-check the destination address, gateway, DNS, proxy reachability, maintenance window, and return path to the documented baseline values.

If the interface displays a restart confirmation, the boundary is a VM restart: NDR and every log collector on the appliance are interrupted. Once the change takes effect, check Appliance Manager at the new IP address, then validate connectivity to Sophos Fusion, NDR upload, SPAN activity, and every log collector as described in section 7. If validation fails and recovery access remains available, revert only the management values changed most recently to the documented baseline. Otherwise, do not try additional network values; escalate with the baseline and visible message.

4. Limit disruption to the smallest component

Only NDR is affected

If the appliance and log collectors are reachable but the NDR sensor is not working correctly, first check upload, SPAN capture, and network flow under NDR. If the issue persists, use Restart NDR.

This restart affects the NDR network traffic analyzer, not the third-party integrations on the same appliance. Nevertheless, it creates a gap in NDR visibility during the restart. Therefore, document the time and duration, then check the NDR indicators again afterward.

Only one log collector is affected

Under Integrations, select the card for the affected integration and capture its status, last restart, and syslog counters before intervening. Restart restarts only this integration. NDR and other integrations on the appliance remain active.

Restart All is appropriate only when multiple log collectors are affected or Sophos Support specifies this scope. The action restarts all third-party integrations on the appliance, but not NDR. It is not a convenient substitute for isolating the issue to one integration.

The entire appliance is affected

Actions > Restart is the next level of intervention if the issue cannot be limited to NDR or one log collector, or if a required appliance restart is pending. It stops and resets every integration on the VM. A restart therefore always causes a simultaneous outage of NDR and all log collectors on this appliance.

Actions > Shutdown stops the appliance and all its integrations. Use this action only when subsequent power-on through the hypervisor, cloud platform, or hardware access is both organizationally and technically assured.

5. Prechecks before restart or shutdown

Before intervening on the entire appliance, all of the following points must be addressed:

  • Scope: The appliance has been verified by name and System ID; all hosted NDR and log collector integrations have been inventoried from Fusion.
  • Impact: Responsible teams know that NDR telemetry and syslog processing will be interrupted simultaneously.
  • Baseline: The Fusion inventory and local version, uptime, tab statuses, and relevant counters have been captured with timestamps.
  • Access: Appliance Manager is reachable; for a shutdown, the power-on path has been verified.
  • Reason for change: The symptoms, expected effect, and success criteria are documented.
  • Maintenance window: A maintenance window and post-intervention observation period have been reserved.
  • Support: Any ongoing log collection or support session has been considered; existing diagnostic evidence has been saved before the restart.

If access for powering the appliance back on is unavailable, Shutdown must not be used as a diagnostic attempt. If only one component is affected, restarting the VM is too broad.

6. Perform a restart or shutdown

To restart the VM in Appliance Manager, select Actions > Restart. For a planned shutdown, select Actions > Shutdown. Do not trigger a second restart or power action in the hypervisor while the action is in progress. This makes it clear which action caused the observed state.

After Shutdown, the expected operational state is that Appliance Manager, NDR, and all hosted log collectors are no longer available. Document this state and the time as the result of the planned shutdown. A stopped VM cannot be powered on from its own Appliance Manager: the responsible person must power it on using the previously verified hypervisor or cloud access.

A shutdown is not a decommissioning, deletion, or erasure procedure. This runbook covers neither deleting an appliance in Fusion nor removing the VM, erasing data, or fully decommissioning the appliance. Do not infer such steps from the visible Delete menu.

7. Validate operation after the intervention

After an NDR, integration, or VM restart, always check the same scope that was documented beforehand. If the appliance remains powered off after a planned shutdown, validation ends with the documented stopped state from section 6. If it is powered on externally, wait until Appliance Manager is reachable again, then perform the complete appliance-, NDR-, and log-collector-level checks. Connected alone is not a substitute for this validation.

Appliance level

  1. Open Appliance Manager again.
  2. Compare System ID and Version with the baseline.
  3. Check whether Uptime is consistent with the restart performed.
  4. Under Status, confirm that CPU, Memory, and the root and data disks are displayed again.
  5. In Fusion, confirm that the appliance is reachable under Integration Appliances and that the expected integrations are still assigned.

NDR sensor

  1. Under NDR, check whether the network flow graph is showing new intervals again.
  2. For every configured SPAN port, confirm that capture metrics appear.
  3. Check whether data is being uploaded to Sophos Fusion again.

A visible appliance status alone does not prove that mirrored traffic is reaching the sensor. Conversely, a single percentage value without new network flows does not demonstrate stable operation. Use multiple consistent local indicators.

Log collectors

For each previously inventoried integration, check the following under Integrations:

  • status
  • time of the last restart
  • new activity under Received
  • traceable processing through Filtered and Accepted
  • Uploaded

For a mixed-use appliance, validation is complete only after both NDR and every log collector have been checked. “Appliance is online” is not a sufficient success criterion.

8. Logs and Sophos Support

Request logs in Fusion

In Fusion, go to Threat Analysis Center > Integrations > Configured > Integration Appliances and select Collect logs from the appliance’s three-dot menu. Log requested documents that the request was sent. Coordinate the subsequent collection and transfer of specific log files with Sophos Support; this operations runbook deliberately does not include a separate download or upload procedure.

Time-limit Remote Assistance

The appliance must be online. In Fusion, go to Threat Analysis Center > Integrations > Configured > Integration Appliances and open Remote Assistance from the appliance menu. In the dialog:

  1. Turn on Enable.
  2. Select the confirmation for the Sophos Group Privacy Notice.
  3. Select Save.
  4. Wait until Fusion displays an Access ID.
  5. Send only the Access ID to Sophos Support through the agreed channel.

Remote Assistance is automatically disabled after no more than seven days. If the analysis ends earlier, turn off Enable in the same dialog. The Access ID is not general-purpose login information and must not be shared with third parties or included in public tickets.

For an escalation, the following is usually sufficient: appliance name, System ID, version, time with time zone, affected workload, observed and expected state, action performed, post-check result, and Log requested status. Do not send passwords or unnecessary complete exports.

Safe operating boundaries

  • No deletion instructions: Delete, VM removal, rebuilding, and data erasure are not part of this runbook.
  • No broad restart as the first step: Start with read-only checks, then restart NDR or exactly one log collector in isolation.
  • No shutdown without a startup path: First ensure access to the hypervisor, cloud platform, or responsible hardware personnel.
  • No simultaneous changes: Do not change network, proxy, SYSLOG, and SPAN values in one inseparable batch change.
  • No credentials in evidence packages: The zadmin password, tokens, and other secrets remain in the password management system.
  • No all-clear based only on “online”: The appliance, NDR, and each log collector need their own success criteria.