This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Log of antivirus

Hello

Could someone provide me with a log of the Sophos Antivirus? Thanks in advance



This thread was automatically locked due to age.
Parents
  • There are many logs of the solution. All ‘detections’ do go to the event log. What are you trying to do? 

  • If I had to pick one log outside of the APIs, Windows App Event log, it would be "C:\ProgramData\Sophos\Endpoint Defense\Logs\ssp.log"  It does have HMPA detections as well, e.g. 

    A Process with path C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe detected as PrivGuard

    Eicar example:
    A File C:\temp\eicar.txt belongs to virus/spyware 'EICAR-AV-Test' (Technical support reference: c7587ff519feda6ee503ab2bb6b72047bef50c5b0e62f812c1c10aa540130904)

Reply
  • If I had to pick one log outside of the APIs, Windows App Event log, it would be "C:\ProgramData\Sophos\Endpoint Defense\Logs\ssp.log"  It does have HMPA detections as well, e.g. 

    A Process with path C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe detected as PrivGuard

    Eicar example:
    A File C:\temp\eicar.txt belongs to virus/spyware 'EICAR-AV-Test' (Technical support reference: c7587ff519feda6ee503ab2bb6b72047bef50c5b0e62f812c1c10aa540130904)

Children