Skip to content
Avanet

Sophos Protected Browser: Reports and Live Discover

Use My Products > Protected Browser > Logs & Reports to create repeatable overviews. For a more detailed investigation, open Threat Analysis Center > Live Discover > Protected Browser and use the built-in Data Lake queries or the Schema Viewer.

These approaches complement each other: reports summarise events in filters, charts and tables, while Live Discover provides individual Protected Browser fields for further analysis. For day-to-day operations, start with a report and move to Live Discover only when the report does not provide enough detail.

Requirements and limits

No specific administrator role or separate Protected Browser permission is documented for Logs & Reports in this workflow. If the menu item is missing, ask a tenant administrator to check the available licences and granted product access. If access is still unclear, refer the case to Sophos Support.

Live Discover requires Sophos EDR, XDR or MDR. It can run two types of query:

  • Endpoint Queries retrieve current information from selected devices that are connected.
  • Data Lake Queries read data from the Data Lake and do not require device selection.

Protected Browser uses Data Lake as its source in this workflow. The Endpoint policy Data Collection and Investigation > Upload to the Data Lake is not a documented requirement or troubleshooting step for Protected Browser data. This workflow changes neither a Protected Browser policy nor data collection.

Create a Protected Browser report

  1. Open My Products > Protected Browser > Logs & Reports.
  2. On the Report Generator tab, choose the appropriate view under Filters > Report templates:
    • Web usage for all internet activity by all Protected Browser users,
    • User authentication for authentication events by user,
    • File transfers for uploads and downloads, including the user, application and status,
    • Browser and Extension for the distribution between the full Protected Browser and the extension, and the browsers on which the extension is installed.
  3. Under Time frame, set the investigation period. With Custom, select the start and end yourself.
  4. Under Query, add a filter: select or enter the column name, enter the comparison value and, if required, change the operator shown on the equals sign.
  5. Select Generate to create the report.

Add filters

Multiple filters are evaluated together: a row appears only if it meets every condition. = and != compare text case-sensitively. The <, <=, > and >= operators are intended for numeric values. IN expects a comma-separated list and is also case-sensitive. ~ and !~ use * as a wildcard and are case-insensitive.

You can use a linked table value directly as a filter. Select the value to add its column and value under Query, then recreate the report with Generate. Use the adjacent delete button to remove a filter.

Configure charts and tables

In Chart, choose Bar, Horizontal bar, Pie, Line or Stack-area. Use the wrench button at the top right to open the axis selector. Set the X and Y axes there; Line and Stack-area also have a Z axis. When you change chart type, Sophos restores that chart’s default axes. Bar and Pie show only the ten most frequent categories, so use the table—not the chart alone—to check completeness.

Table initially displays a default set of columns. Use the column selector at the top right to show additional fields, and use the column headings to sort in ascending or descending order. Additional columns provide more detail, but also make exports wider and may expose more personal information.

Schedule and export reports

For a one-off export, select PDF, CSV or HTML under Generate an export manually. The resulting export appears under Scheduled Exports. Exported reports are deleted after 90 days.

To configure a recurring export:

  1. Select Schedule.
  2. Enter a name under Template Name. The limit shown is Maximum characters for the name: 64.
  3. Under Time frame, select the period covered by the data.
  4. Under Export frequency, select Daily, Weekly or Monthly. For a weekly export, choose a day of the week; for a monthly export, choose a day of the month.
  5. Under Duration, select Until I cancel or Ends on and provide an end date.
  6. Under Export format, select PDF, CSV or HTML. Configure notification or delivery under Export notification/delivery, then select Save.

You can create up to 200 export schedules. If a report contains personal information, Sophos recommends emailing a link rather than attaching the report directly. The link requires Sophos Central credentials. Delivery goes to the email address recorded under Account Details; you can also select other Sophos Central administrators as recipients.

Save Template preserves query filters, the chart type and axes, table sorting, and table columns. It does not save the data or time period. A saved template therefore defines the presentation, not the next investigation period. Under Saved Templates, use Update to update a template or Delete to remove it; you can also enable or disable its export schedule.

Investigate Protected Browser data with Live Discover

Sophos provides built-in Data Lake queries for Protected Browser. To run one:

  1. Open Threat Analysis Center > Live Discover and select Protected Browser.
  2. In Query, choose the required category and then a built-in query. Review the displayed query details to confirm that the query suits your investigation.
  3. Under Select a Time Period, set the period. The default is seven days, and each run can cover no more than 30 days. If you know when a test occurred, begin with the shortest practical period.
  4. Select Run Query at the bottom and review the returned results.

The time period limits the data returned by this single run. It does not create a schedule and is not the same as a scheduled query. To edit or create a query, enable Designer Mode; for a new Protected Browser query, select Data Lake as the Source.

To open the current Data Lake schema:

  1. Open Threat Analysis Center > Live Discover > Protected Browser.
  2. Enable Designer Mode.
  3. In Query, select an existing query and select Edit, or select Create new query.
  4. At the top right of the SQL dialogue, select Schema.
  5. In the new tab, select Protected Browser from the Data Lake list.

The current Schema Viewer is the authoritative source for exact, non-translatable SQL identifiers and for the available tables and fields. The product documentation does not unambiguously specify the gateway identifier’s spelling, so this guide does not provide either a copyable field list or an unverified SQL query. Copy customer, gateway and application-category identifiers exactly as they appear in the current Schema Viewer. For a safe starting point, use a built-in query over a short period.

Interpret Protected Browser fields

The fields displayed in the Schema Viewer can be grouped by their documented purpose: identity and application; time and event; policy and access; client and origin; Endpoint status; agentless RDP/SSH; and file transfer. Copy every required identifier directly from the viewer without translating it or normalising its spelling. This applies explicitly to the customer, gateway and application-category IDs described there.

For log_type, the documented exact values are Navigation, SSH, RDP, Login and Logout. The protocol-subtype field indicates whether access was allowed. An empty value does not necessarily indicate an error: some fields apply only to particular event types or prerequisites. For example, Synchronised Security health status is available only when Sophos Intercept X is installed, and file details are relevant only to file transfers.

Validate the result

A small activity at a known time helps avoid mixing old and new events. For example, ask a designated test user to open an approved application, then check the following:

  1. The appropriate report contains a row for the user and application within the selected period.
  2. Filtering for the same user or application reduces the table as expected.
  3. For Bar and Pie, the displayed top-ten categories and their aggregation agree with the corresponding table values. The table remains the reference for the complete result set.
  4. A built-in Protected Browser query in Live Discover returns matching event details for the test time within the short selected period. Check the required fields against their descriptions and exact spelling in the current Schema Viewer.

The query source must be Data Lake. Device selection applies only to Endpoint queries and is therefore not an appropriate validation step for Protected Browser Data Lake data.

Troubleshoot by symptom

The report is empty

First, remove or widen the time restriction or filters under Time frame and Query, then recreate the report with Generate. Choose a template that matches the test activity: a sign-in belongs in User authentication, while an upload or download belongs in File transfers. If an unfiltered report for known activity is still empty, stop this diagnostic workflow. Check that Protected Browser events are being generated and verify product access. If the cause remains unclear, refer the case to Sophos Support.

A filter unexpectedly returns no rows

For =, != and IN, first check the spelling and letter case. To match a substring, use ~ with *. If there are several filters, test each one separately because a row appears only when it meets every condition.

The chart and table appear inconsistent

For Bar or Pie, first check whether there are more than ten categories: these charts show only the top ten. Changing the chart type also restores its default axes. Check the axes using the wrench button, and use the table for a complete detailed review.

Live Discover does not show the expected details

First, confirm that Protected Browser is selected, the query uses Data Lake as its Source, and Select a Time Period includes the known activity. Then open the Schema Viewer and use the field description to determine whether the expected detail can be populated for the event type under investigation. For example, Synchronised Security health status requires Sophos Intercept X, and file details are relevant only to file transfers. If a built-in Protected Browser query remains empty for known activity, check that the Protected Browser activity is being generated and verify product access. The Endpoint upload policy is not a documented remedy for Protected Browser data. If the cause remains unclear, refer the case to Sophos Support.

Safe rollback and ongoing operation

Report filters and presentation changes do not alter a protection policy. To return to a known state, remove the added filters or reload the report with the required template. Under Saved Templates, remove a saved template with Delete.

Before making a change, record the name, recipient, format and last required export. To give an existing Until I cancel schedule an end date, select it under Scheduled Exports, select Update, and change it to Ends on if the interface permits. If it cannot be updated, complete and record this check before removing the old schedule with Delete, then create its replacement with Ends on. Finally, confirm that only the intended schedule is active and that no duplicate exports or deliveries will occur.

For ongoing operations, regularly review saved templates and schedules for their purpose, recipients and required data fields. Remove exports that are no longer needed before copies containing personal data are distributed unnecessarily. Sophos Central deletes exports after 90 days, so any required longer retention must be managed in your own controlled data lifecycle. Before changing a custom Live Discover query, record its existing version separately; no product-side versioning or rollback mechanism is documented for this workflow.

The Endpoint Data Collection and Live Discover guide explains general Live Discover query types and operational query limits. However, its Endpoint upload policy applies only to Endpoint telemetry; it is neither a requirement nor a remedy for Protected Browser data.