Skip to content
Avanet

Operate the Sophos NDR Investigation Console Safely

The Investigation Console provides data from assigned NDR Integration Appliances on the local network. This guide describes local user management, review of audit and system data, and safe interventions on the console.

Before any change, identify the correct console and preserve the baseline state. Use Restart and Shutdown only after approval and with a prepared recovery path. SPAN/TAP coverage, sensor health, and complete appliance decommissioning are not part of this guide.

Responsibilities of the two interfaces

Sophos Fusion and the local Investigation Console have different tasks:

TaskInterfaceOperational boundary
Find and open the consoleSophos Fusion, My Products > NDR > Investigation Consolecentral entry point
Review assigned appliancesSophos Fusion or locally under Investigation Appliancesinventory and resource view
Manage local userslocal console, User Managementadministrators only
Trace administrative actionslocal console, Audit Loglocal audit evidence
Check console resources, network, pods, and health logslocal console, System Detailsconsole health, not sensor health
Configure or diagnose an applianceManage Appliancehandoff to Appliance Manager
Request console logs centrallySophos Fusion, console menu Collect Logsdiagnostic request
Grant time-limited appliance support accessSophos Fusion, console menu Remote Assistantaccess to the appliance hosting the console
Grant support access to the Sophos Fusion sessionProfile > Support settings > Remote Assistancedifferent permission scope and duration

Before any action, record the console name, IP Address, Version, platform under Type, assigned Appliances, CPU, and Memory in Sophos Fusion. In the local console, also record the name, uptime, time, and time zone. Never distinguish similarly named consoles solely by their browser tabs.

Open console and protect access data

In Sophos Fusion under My Products > NDR > Investigation Console, search for the desired console. In the three-point menu, select Open NDR Console, confirm the notice to leave Sophos Fusion and log in with the provided access data.

For access managed by Sophos Fusion:

  • A forgotten password can be reset in the Open dialog via reset it.
  • Alternatively, open the three-point menu on the console line and select Generate New Password.
  • Copy the new password immediately into the shared password system. It is displayed only once and cannot be retrieved later.
  • Only then confirm Reset and test the new sign-in in a separate browser window.
  • Passwords do not belong in tickets, screenshots, audit exports or operating logs.

A password change can relate to access documentation and stored emergency procedures. Therefore, before resetting, check the responsible person and the destination account. Delete the old password only when the new one is safely stored and the login is checked.

Managing Local Users and Roles

Only an administrator can open User Management. On the Active tab, the console shows Username, Email and Role. With Filter, you can search for Username, Email and Role; Save applies the criteria, Clear removes them.

The Super User created in Sophos Fusion is grayed out. This account and its password are managed in Sophos Fusion, not with local user actions. The Super User can also create administrators for Investigation Console in Sophos Fusion. Before any change, it must therefore be clear whether it is the Fusion-managed Super User or a local user.

Adding Users

Under Actions > Add User, fill in the following fields:

  1. Full Name, Username and Email.
  2. Activate Administrator only if the person needs local user and system administration.
  3. Enter and confirm an individual password.
  4. Select Save.
  5. Perform a controlled sign-in to confirm that the account works and the role matches the request.
  6. Check in Audit Log that the administrative action is traceable.

Leaving Administrator cleared is the safe default. Avoid shared accounts; Username and Email should be associated with a responsible person or documented technical account.

Lock or unlock account

A lock is the preferred immediate measure if access is temporarily stopped but the data set is not yet to be removed:

  • In the user’s three-point menu, select Lock Account and then select Lock. The lock symbol must appear next to the account.
  • To restore access, select Unlock Account and then Unlock. The lock icon must disappear.

After locking or unlocking, check user list and Audit Log. Unlock only when identity and blocking reason have been clarified and the password has been changed if necessary. Multiple failed logins are not covered by repeated unlocking.

Reset local password

User Management supports resetting local passwords. First, clearly identify the user via Username, Email and Role and ensure that the grayed-out Super User managed by Sophos Fusion is not affected. The product documentation does not describe the full click path nor whether existing sessions are terminated. Therefore:

  1. Document the baseline and request.
  2. Use only the action offered in the line of this local user to reset.
  3. Pass the new password exclusively via the shared secret channel.
  4. Verify the new sign-in and correct role.
  5. Preserve the audit event and do not assume that active sessions have ended without checking.

Don’t confuse it with Generate New Password: This action is on the console in Sophos Fusion and affects the console access managed there.

Remove users and observe 30-day limit

For a planned removal, check first whether locks are sufficient and whether audit documents are already exported. Thereafter:

  1. On Active mark exactly the desired user.
  2. Select Actions > Remove User.
  3. Check the destination account again and confirm it with Remove User.
  4. Check that the user no longer appears under Active, but under Deleted.

A removed user remains under Deleted for 30 days and can be restored only within that period. The period begins when the user is removed, so record the removal time and time zone in the ticket. Before restoration, recheck the identity, approval, required role, and reason for the lock; then verify sign-in, Role, and the audit event.

The product documentation does not specify an additional grace period or a recovery after the 30 days have elapsed. If the period has expired or is unclear, do not present a replacement record as a restoration. Hand the case and existing audit evidence to Sophos Support. Also, removing a user does not delete all historical audit or investigation data.

Filter and export audit log

The Audit Log shows administrative actions with Username, Details and Date/Time. It is the first source for the question of who in the console made an administrative change when.

For the evaluation of an incident or change:

  1. Open before further changes Audit Log.
  2. Select Filter.
  3. Set Username, Details Keyword, Start Date and End Date as required.
  4. With Save apply and check whether the time period and hits match the question.
  5. Use Export CSV to download the required audit evidence to the local device.
  6. Document file name, download time, time zone, filter criteria and location in the ticket.
  7. Return to the unfiltered view with Clear.

A filtered export is not proof that no action took place outside the filter. For a security investigation, also review a sufficiently broad time period. The CSV can contain usernames, email addresses and administrative details and belongs in an access-protected case filing, not in a public chat or unprotected ticket.

Check assigned appliances and hand them over cleanly

Under Investigation Appliances, the console shows for each assigned appliance:

  • Appliance Name
  • CPU and Memory
  • Storage 1 for the root drive and Storage 2 for the data drive
  • Type
  • Management IP and Syslog IP

In Sophos Fusion, the console line can also be unfolded. For each assigned appliance, Appliance name, Integrations, Memory, Storage, Type, Version, Management IP and Syslog IP are visible there.

This information is used for identification and comparison. You need to configure or examine an appliance, open the three-point menu in the right column and select Manage Appliance. The Appliance Manager opens in a new tab. When handed over, include at least console name, Appliance Name, management IP, version, observation time, visible resource deviation and last change.

Use system details as a reference

System Details shows the Investigation Console name, uptime, CPU, memory, and data usage. For comparison, record a timestamped baseline. These include Stats with CPU Usage, Memory Usage, HDD Root Usage, HDD Data Usage and CPU Logical Processors, the current values of the Management Interface and Web Proxy under Settings, eye-catching entries under Advanced, relevant Health Logs as well as the assigned appliances and their visible resource values.

No universal alert thresholds are documented for these values. A single high reading therefore does not prove a cause. Consider the trend, your own reference values, concurrent errors, and whether the root or data drive is affected. Do not manually delete files or containers to free storage.

Before and after changes

The following are the common checklist for user, network, proxy, restart and support actions:

  1. Identity and baseline: Record the console name, IP address, platform, version, uptime, assigned appliances, and time with time zone. Capture Stats, Advanced, Health Logs, and, if necessary, the Audit Log or log ZIP.
  2. Change: Document the request, approval, responsible person, maintenance window, expected impact, success criteria, and rollback plan. Do not change a second setting or system layer at the same time.
  3. Access and role: Sign in with an authorised account and verify its Role and approved access. A locked or removed test account must not receive the intended access; do not deliberately lock production accounts for negative testing.
  4. System and connections: Compare uptime and Stats with the baseline. Under Advanced, select Refresh and check Ready, Status, and Restarts. During the observation period, Health Logs must not show a continuing new fault in connections to the Integration Appliances.
  5. Appliances and evidence: Check the expected assignments and management addresses under Investigation Appliances. Verify the action in Audit Log and disable Remote Assistance when it is no longer required.

Continue the observation over a time period appropriate to the environment. A reachable sign-in page or a one-time Running status does not yet prove stable operation.

Change the Management Interface in a controlled manner

Under Settings at IPv4 Configuration with Edit, select between DHCP and Static. Static requires IPv4/Netmask, Gateway IP and DNS; DNS 2 is optional. The DNS addresses may be private or public. With Save the change is adopted.

Before selecting Save, make sure that:

  • new IP address, network mask, gateway and DNS are confirmed by the network managers,
  • DHCP prepares the required address reservation,
  • the firewall, routing, and DNS paths to Sophos Fusion and the assigned appliances have been clarified,
  • Browser access via the new address and an administrative return via ESXi or Hyper-V are available,
  • Baseline values, maintenance window and reset plan are documented.

A management IP change can end the current session. Do not simultaneously change proxy, DNS and IP configuration; otherwise, the cause of a connection loss cannot be clearly determined.

Changing the Web Proxy

Under Settings at Web Proxy, select Edit and then Enable Web Proxy. For Web Proxy Type, Anonymous and Authenticated are available. For Authenticated, Username and Password are required; in addition, Hostname and Port are set.

Proxy credentials are not captured in screenshots or tickets. Before saving, have the proxy owners confirm reachability, name resolution, port access, and authentication. After the change, check both the connection to Sophos Fusion and the connection to the assigned appliances. Successful local login alone does not confirm the external path.

Read Advanced and Health Logs

The Advanced tab shows the console’s Kubernetes pods with Name, Ready, Status, Restarts and Age. Possible Status values are Pending, Running, Succeeded, Failed and Unknown. Ready shows running in relation to existing containers, for example 1/2. The Refresh icon at the top right updates the status values.

A pod restart or another status is initially a finding, not a cause by itself. Record the name, Ready, Status, Restarts, Age, and time. Do not run Kubernetes commands, delete containers, or restart pods manually on suspicion.

Health Logs records the processes that handle connections between the Investigation Console and the Integration Appliances. It shows Level, Module, Message, and Date/Time. Use Filter to narrow by Keyword, start date, and end date.

For analysis:

  1. Set time window on the onset of the fault and the last known functioning observation.
  2. Record the affected Module, exact Message, Level, and time with time zone.
  3. Compare the same time window with Advanced, Uptime, Resources and the Audit Log.
  4. Remove the filters and check whether the broader history changes the interpretation.

Empty filtered Health Logs do not prove that the connection is error-free.

Secure diagnostic packages before an intervention

There are two documented log paths with different starting points:

  • Download a ZIP file locally under System Details > Actions > Download Log File. This package is comparable to the log package of an integration appliance, but not equated with it.
  • In Sophos Fusion under My Products > NDR > Investigation Console in the three-point menu of the console select Collect Logs.

Before Restart, Shutdown or a network setting, execute Download Log File first and additionally export the current Audit Log. Name the ZIP and CSV files after the console, time, and time zone; store them securely and submit them only through the approved support channel. Logs may contain personal or environmental data. Do not “clean” access data by making changes to the original package; instead, coordinate content and transmission with Sophos Support.

Collect Logs is a request, not proof that an expected local package is already available in full. Document the time of the request and clarify with Sophos Support which file is needed for the specific case.

Restart and Shutdown Safely

Under System Details > Actions, Restart and Shutdown are available for Investigation Console. The interruption applies to all users of this console and to the local view of the data of all the appliances assigned to it, not only to the session of the person performing the action. Login, local queries and administration are not available during this time.

The product documentation does not guarantee that data generated during the interruption will be completely buffered, later supplied or restored seamlessly for local investigations. Therefore, treat the window as a possible visibility and examination gap and promise no recoverability.

Additional conditions

In addition to the central checklist, ongoing analyst queries and support work must be coordinated. It requires an approved maintenance window, access to the console VM in VMware ESXi or Microsoft Hyper-V, and the assurance that no network, proxy, hypervisor, or appliance change is running in parallel. For Shutdown, a tested external way to reactivate and a responsible person must also be available.

Action and follow-up

For a planned restart Actions > Restart, for a shutdown use Actions > Shutdown. Trigger the action only once and do not simultaneously force a restart or shutdown in the hypervisor.

After Restart, wait until the local login can be reached again and check using the central checklist. After Shutdown, the console must be unreachable as expected. Document time and only switch it back on via the prepared ESXi or Hyper-V path.

Remote Assistance and the support boundary

Two similarly named functions grant different access:

Appliance access for maximum 24 hours

If Sophos Support requires remote access to the appliance running Investigation Console, the appliance must be online. In Sophos Fusion, open on the Investigation Console page in the three-point menu Remote Assistant. In the dialogue Remote Assistance:

  1. Activate Enable.
  2. Check the Sophos Group Privacy Notice box.
  3. Select Save.
  4. Wait until the Access ID is displayed.
  5. Only send this Access ID via the agreed channel to Sophos Support.

This access is automatically deactivated after 24 hours. If the work is completed earlier, turn off Enable in the same dialog. Document activation time, ticket number, recipient, expected expiration date and manual deactivation. Do not send the Access ID in public tickets or to uninvolved third parties.

Access to the Sophos Fusion Session

The link Sophos Fusion in System Details leads to the central interface. Under the profile icon Support settings > Remote Assistance, there is a separate support access to the Sophos Fusion session. It is switched off by default and can be granted for 3 days, 7 days, 14 days, 30 days or 60 days; standard is 7 days. The expiration date and time are displayed.

Do not confuse this portal access with the 24-hour appliance access. Grant only the permission scope required for the support Case and the shortest appropriate duration, then disable it when the work is complete. Partner Assistance is another permission and is not activated as a replacement for Sophos Support.

Sophos Support helps with installation, administration and operation, non-documentation-related product behavior and general configuration support. A reimplementation, comprehensive redesign, or customer-specific queries are not automatically included.

For the support case, first specify console identity, version, uptime, time with time zone, observed and expected status, last change, affected appliance, relevant audit and health events and the log package. Do not send passwords.

Isolate errors systematically

Console cannot be opened from Sophos Fusion:

Check the console row, IP Address, version, CPU, and memory, and record the exact error and time. Then check management routing, DNS, browser access, and the VM console in ESXi or Hyper-V. Test password problem and network accessibility separately: Generate New Password does not fix an incorrect IP, DNS, routing, or proxy configuration.

Sign-in fails:

First, clarify whether the access managed by Sophos Fusion or a local user is affected. Check for a local user under User Management block status, Username, Email and Role. Only unlock or reset the affected account. For Sophos Fusion managed console access, use reset it or Generate New Password, respectively. Do not share passwords between users.

A user or audit event appears to be missing:

Check Active and Deleted and remove all filters with Clear. In the Audit Log Username, period and Details Keyword individually check. A user under Deleted can only be treated as recoverable within the documented 30-day limit. An empty filter is not proof that no event exists.

An appliance is missing or shows unusual resource use:

Compare the assignment in Sophos Fusion with Investigation Appliances. If the name, Management IP, or assignment does not match, do not change console network settings as a corrective attempt. Use Manage Appliance to hand the issue to the person responsible for the appliance.

Pod is not ready or repeatedly restarts:

Under Advanced, select Refresh and record the name, Ready, Status, Restarts, and Age. Check the same time window in Health Logs, Stats and Audit Log and run Download Log File. Do not manually change pods or containers. If the status remains Pending, Failed, Unknown, or not fully ready, escalate to Sophos Support with the log package.

Connection to appliances is disrupted:

Filter in Health Logs by time window and Keyword and save Module, Message and Level. Then compare Management Interface, Gateway, DNS and Web Proxy with the last approved state. Do not change several settings at the same time. Identify the appliance separately and pass the detail check to the appliance manager.

Root or data usage is increasing:

Record the time series and concurrent pod and health events, and preserve the audit CSV and log ZIP. Without a documented threshold, do not define an arbitrary percentage as a failure limit or delete files, pods, or data manually. If growth continues or functionality is impaired, involve Sophos Support with the reference values and trend.

Restart does not resolve the symptom:

Do not start a restart loop and do not escalate with Shutdown. Compare values before and after the intervention, uptime, logs and timeline. If the same fault persists, preserve the unchanged evidence and grant support access with the minimum required permissions. A restart without a clarified cause is not a completed problem solution.

Handoff checklist

When transferring operations or support, do not repeat the central checklist, but complete:

  • Ticket number and agreed support scope
  • Protected storage locations of Audit-CSV and Log-ZIP and time of Collect Logs
  • Action executed, measurable outcome and next responsible person
  • Status, expiration time and agreed deactivation expiration of a possible Remote Assistance