This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Endpoint - Cryptoguard Log Location

My employees accidentally cleared an alert in Sophos Central for a ransomeware attack. Doing so erased all the detail information (File locations, etc.) Can someone point me to the log location so I can get that information from the log?



This thread was automatically locked due to age.
Parents
  • Hi Kyle,

    Thanks for reaching out to the Sophos Community Forum.

    You can find the detailed analysis by navigating to the device in question within Sophos Central to view the Events list, wherein you'll find a "Details" button on the detection event. 

    You can also find these details recorded in the Windows Application Event Log locally on the device. By filtering for the event ID 911, you'll see a list of all Intercept X detections. 

    Kushal Lakhan
    Team Lead, Global Community Support
    Connect with Sophos Support, get alerted, and be informed.
    If a post solves your question, please use the "Verify Answer" button.
    The New Home of Sophos Support Videos!  Visit Sophos Techvids
Reply
  • Hi Kyle,

    Thanks for reaching out to the Sophos Community Forum.

    You can find the detailed analysis by navigating to the device in question within Sophos Central to view the Events list, wherein you'll find a "Details" button on the detection event. 

    You can also find these details recorded in the Windows Application Event Log locally on the device. By filtering for the event ID 911, you'll see a list of all Intercept X detections. 

    Kushal Lakhan
    Team Lead, Global Community Support
    Connect with Sophos Support, get alerted, and be informed.
    If a post solves your question, please use the "Verify Answer" button.
    The New Home of Sophos Support Videos!  Visit Sophos Techvids
Children