Feature request

It happens now and then that the Endpoint finds a PUA or something else that (for some reason) it cant clean by it self.

Sometimes it is actually gone so you cant manually clean it either.

So a included script in the integration to clean the events like this:

https://community.sophos.com/products/sophos-central/f/general/92198/remote-quarantine-cleanup/413330

Whould be really handy. Is this something that might be in the integration in the near future?

 

Script is found here: https://github.com/ir0nh3at/Scripts/blob/master/Sophos%20Stuff/Sophos.psm1

 

Thanks.

Parents
  • Hi Eric,

    What your referring to is an Endpoint Product issue and not something that we'll be addressing with the Sophos Central Plugin. Clear the database and recreating it is a manual/scripted fix from the Endpoint Security Group. This is already something that they have on their roadmap to address and fix.

    Clearing Alerts from Sophos Central will be something that we will be added in a future release.


    Thanks,

     

    Steve

Reply
  • Hi Eric,

    What your referring to is an Endpoint Product issue and not something that we'll be addressing with the Sophos Central Plugin. Clear the database and recreating it is a manual/scripted fix from the Endpoint Security Group. This is already something that they have on their roadmap to address and fix.

    Clearing Alerts from Sophos Central will be something that we will be added in a future release.


    Thanks,

     

    Steve

Children
No Data