This article provides information on the various log files used by each of the Sophos Endpoint Security and Control components. The presence of the log files below will depend on whether the specific component is installed or active. For server-side log files see article 116523
Jump to the relevant component using the following links:
Sometimes referred to as the 'AutoUpdate log'. This file contains logging information relating to the update of system components. You must use the 'Sophos log viewer' to read this file (launch from Sophos Endpoint Security and Control by clicking on 'View Updating Log') . Log level can be set in the Sophos Enterprise Console in the updating policy for a group. On the logging tab select 'Normal' or 'Verbose'.
Every comment submitted here is read (by a human) but we do not reply to specific technical questions. If you need technical support please post a question to our community. Alternatively for licensed products open a support ticket.