Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Central Reporting - is it really working?

I keep hearing about the Central Reporting and how all the detailed logging is available through it, which has plenty of data points and filters.

We are subscribed to Xstream Protection, which includes Central Orchestration, which includes 30 days of logs. Never had to go deep for analysis.

A few days ago I was tasked to track a user. So I went to Sophos Central Reporting to pull the data.

Immediately it looked weird. So I opened Log Viewer on the firewall and started comparing. Central has nothing even close to the data available through the Log Viewer.

I pulled the VPN log file from the firewall to trace connection times and compared with the Central Reporting. Absolute inconsistencies, missing data.

Here's one example for Rule ID=1 DROP ALL and LOG. I am not going to post many other inconsistencies with VPN and FW Rules because there are too many.

DST PORT 3389 is being blocked:

Applied Filter DST Port 3389:

Changed filters to Rule ID = 1

Has anyone experienced the same thing? Can you check on your end? I can't trust the Central Reporting and it's a serious Security matter, that might put user's employment under question.

Before anyone suggests a syslog server, I don't recall Sophos reps mentioning that Xstream License that included 30-day logging and granular Central Reporting was in fact waste of money, and I should be going with the Standard license instead.



This thread was automatically locked due to age.
Parents Reply
  • I tried the search in Central and also got no results. Of course, there is something logged, but as soon as I narrow down the filter, the less it shows until nothing.

    SFOS (SFOS 19.5.2 MR-2-Build624)

    As an example I wanted to find only dst port 161 blocked by rule 5 at 11:53 AM

    We can see Port 161 logged at that time when I leave out the rule 5 filter

    Filter for  log subtype denied:

    if I remove the port, I can see many denied but no with port 161

    Same is when I  export the log from central and search in the CSV

Children