This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Intercept X Endpoint - Random auto-isolation on company computers

I am aware that self-isolation happens due to the "health" factors of the computer.

However, would there be somewhere, some log that I can see exactly the cause of this self-isolation?

Clients are automatically isolated for less than a minute often, so I needed to know the exact cause of the isolation. (Central/Client)



This thread was automatically locked due to age.
Parents
  • Thank you for reaching the community forum, 

    Was the Isolation happen on the same devices? How many days have you observed such behavior on your manage endpoint? are you getting any alerts on central prior to receiving the isolation alert? 

    Glenn ArchieSeñas (GlennSen)
    Global Community Support Engineer

    The New Home of Sophos Support Videos!  Visit Sophos Techvids
Reply
  • Thank you for reaching the community forum, 

    Was the Isolation happen on the same devices? How many days have you observed such behavior on your manage endpoint? are you getting any alerts on central prior to receiving the isolation alert? 

    Glenn ArchieSeñas (GlennSen)
    Global Community Support Engineer

    The New Home of Sophos Support Videos!  Visit Sophos Techvids
Children
  • Hi!

    Most of the time isolation happens on the same device, but some others are self-isolating as well.

    In Sophos Central, only the event logs appear, when a file is considered malware and is deleted from the machine, but I still haven't found in the Logs and Reports the exact cause of the isolation of each computer, I also don't know if there is a log level like that .

    Happens since Endpoint implementation.

    Software Developer, FOSS Contributor & Linux Administrator

    Member at Free Software Foundation