Sophos Central Peripheral Control - Purge Events?

Hi,

I have Central managing over 8800 active endpoints, we use Peripheral control. 

There are close to 24000 peripherals listed in our organisation, 2180 of which are currently

allowed. I have historic data going back 4 years.

To find new events in the standard reporting view https://cloud.sophos.com/manage/endpoint/reports/protection/peripherals/create/all I cannot

sort by date or the last action or user so I have to export as CSV and search with Excel or similar, if I could base it on the last hour, day, week or month etc.

similar to the policy - Add Peripheral Exemptions, I could work with it. 

Is it possible for me to be able to accept that peripherals are blocked such as "Apple iPhone" "Samsung Mobile USB Modem" - Block but don't report.

If I could do an export for historical purpose then purge the log I would be in a better place.



Edited tags
[edited by: Gladys at 7:11 AM (GMT -7) on 19 Jun 2023]
Parents
  • Hi  ,

    Thank you for reaching out to the Community Forum.

    Sorting the data by date or last action directly in the "Peripheral Report" doesn't seem to be an option currently. You'll have to export the data first to sort them.

    But if you'd like this specific feature added, you can send this as a feature request. Kindly reach out to your Account Manager to do so.

    Is it possible for me to be able to accept that peripherals are blocked such as "Apple iPhone" "Samsung Mobile USB Modem" - Block but don't report.

    Can you clarify what you mean by this, please? Do you not want these detections to send a notification to the users? If that's what you're trying to do, you may toggle off the desktop messaging option on your Peripheral Control policy.

    I hope this helps. If I somehow misunderstood your question, please let me know.


    Gladys Reyes
    Global Community Support Engineer
    Are you a Sophos Partner? | Product Documentation | @SophosSupport | Sign up for SMS Alerts
    If a post solves your question, please use the "Verify Answer" button.
    The New Home of Sophos Support Videos!  Visit Sophos Techvids
  • Hi Gladys.

    I refer specifically to the logs. Is it possible to acknowledge that a device has been blocked. eg.

    User A connects an iPhone on Monday to charge their device. (Blocked by policy, log updated)

    User A connects their iPhone on Tuesday to charge their device. (Blocked by policy, log updated)

    User B also connects an iPhone that is blocked everyday.

    The Admin looking at the logs know that it has been blocked, cant do anything with that information - The growth is exponential.  

    Block but dont log it everytime.

Reply
  • Hi Gladys.

    I refer specifically to the logs. Is it possible to acknowledge that a device has been blocked. eg.

    User A connects an iPhone on Monday to charge their device. (Blocked by policy, log updated)

    User A connects their iPhone on Tuesday to charge their device. (Blocked by policy, log updated)

    User B also connects an iPhone that is blocked everyday.

    The Admin looking at the logs know that it has been blocked, cant do anything with that information - The growth is exponential.  

    Block but dont log it everytime.

Children