I have some questions on the reporting we get out of the Sophos Centra API. We are seeing a discrepancy between client health status se see in the web interface and the reports we generate from the API. As an example I have a computer that shows in the web ui critical status, but when we pull a report from the API this computer shows overall health status of good, but with 1 high alert error of real time protection disabled. This seems a bit off that a computer would have a high severity alert but still have a good health status.
Does anyone know of any documentation for what triggers the different health statuses we see in the API reporting vs what we see in the web ui? We are trying to build some automations, but it is difficult with what seems like inconsistent reporting.
Added TAGs
[edited by: Qoosh at 7:25 AM (GMT -7) on 17 Jun 2022]