This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

More detail in logs/reports?

I was recently posed the question regarding the Logging and Reporting of the events that is stored in the Console for Sophos Central?  For instance, for one of our users, in the last couple days or so, we are trying to determine why there is nearly 4,000 entries of a blocked item:

'tse4.explicit.bing.net' blocked due to category 'Adult/Sexually Explicit'

Any information would be greatly appreciated, as to determine perhaps the page, or element on the page that is causing this to be flagged in Sophos, as the URL is not one a user would key in from scratch, but likely an advertisement that happens to reference the URL, but when reviewed in the console, it does not give detailed information as to how to determine this.

In addition, are there means of re-categorizing some of the alerts that are collected?  For instance, Facebook is often visited - as we have two departments here who use it for advertising and promoting events, and is flagging the category of "Dating and Personals" yet it seems to make more sense as a "Social Networking" category rather than Dating/Personals.

Thank you very much, once again, for your time, and assistance in advance. 

Regards,

-James Granell, Granite Associates, LP, IT Department.



This thread was automatically locked due to age.
Parents
  • Maybe not a full answer but you can re-categorise sites under:
    https://cloud.sophos.com/manage/config/settings/websites-tagged

    and then tag these in your policy.

    As for the alerts, if you can check the browser history at the time of the event then you might get a rough idea of the sites accessed during that time.  With the Developer tools open of the browser (f12) at the network tab you should may see maybe a 403 response code for a blocked component.  From the Developer tools you can determine where the resource query came from.

    Regards,

    Jak

Reply
  • Maybe not a full answer but you can re-categorise sites under:
    https://cloud.sophos.com/manage/config/settings/websites-tagged

    and then tag these in your policy.

    As for the alerts, if you can check the browser history at the time of the event then you might get a rough idea of the sites accessed during that time.  With the Developer tools open of the browser (f12) at the network tab you should may see maybe a 403 response code for a blocked component.  From the Developer tools you can determine where the resource query came from.

    Regards,

    Jak

Children
No Data