• Custom Reports - Seeing Websites User Visited

    Hey Help Desk Guy
    Hey Help Desk Guy
    Hi all, So exported a custom report web surfing report and it contains a lot of information. Is there a way to see just the sites the person visited rather than all other erroneous traffic like certs, etc?
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Troubleshoot Dropped Traffic

    Jmes03
    Jmes03
    Im trying to figure out why traffic is being dropped between Lan and VPN. I have the firewall rule made to allow traffic. Traffic is passing fine except for traffic on 1 port. It is not showing in the Log but it i did drop-packet-capture this pops up…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Logging issues

    Memorycard
    Memorycard
    Hello everyone, I've configured one of our Sophos devices with some rules and policies . The problem is with the amount of Logs it generates per second! There are too many Information level logs about WAF and other types of log components. So it…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • How to explain this log?

    Michal Talman CZ
    Michal Talman CZ
    Hi, I have rule 5. It's a DNAT from the WAN IP 188.175.113.182 in to the network to the VoIP server. If I look in the LOG, I see the following: The first line does correspond to rule 5, but what do the other lines mean? They are also marked…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Report's - See Device Name

    Hey Help Desk Guy
    Hey Help Desk Guy
    Hi Sophos community, Is there a way to see device reports by device name? In other Firewalls I had this option but it doesn't seem to be an available feature thru Sophos.
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Microsoft 365 Defender (Cloud App Security) Log Upload

    Ben@Network
    Ben@Network
    Hi all, we want to upload the Sophos XG Logfiles to Microsoft 365 Defender (Cloud App Security). In general the Logfiles are received by Microsoft but in the wrong format. On the Sophos XG we selected "Standard Syslog protocol" and on Microsoft site…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Is there a way to export an entire report?

    Hey Help Desk Guy
    Hey Help Desk Guy
    I'd like to export an entire report to PDF from Sophos Firewall but it won't let me. For example, this report is 14 pages but I can only seem to export 200 records max.
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Log viewer filter more than one port?

    TheGewp
    TheGewp
    Is it possible to filter more than one port in the log viewer? I am trying to find some specific traffic and i want to exclude both 443 and 123 but I cant seem to stack the filters. Thanks!
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • tracing a IP

    Muhammad Alyas Qaisar
    Muhammad Alyas Qaisar
    Dear Sir How and where I trace a Local IP address that is consuming my Internet? Thanks Muhammad Alyas Qaisar
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Pakets not in firewall log

    Quallensaft
    Quallensaft
    (simple ANY rule with a lot of traffic -> should be in LOG)
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos XG 19.5.2 - DHCP stopped logging in System

    Corey Carpenter
    Corey Carpenter
    Hello, Shortly after we updated to XG 19.5.2 we noticed that DHCP renewals were no longer logging in the System logs of the live viewer. There are no "DHCP Server" events shown at all. There have been no config changes since the update and DHCP is still…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XGS 87 no reports in Sophos Central

    BassmanB
    BassmanB
    I have a xgs 87 and reports were working fine all of a sudden they just stopped - unit showing connected in sophos central. Have removed and re added also to no avail. how do i get reports working again. PS have done the obvious thing and restarted…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Missing Zones in Logs

    Quallensaft
    Quallensaft
    Is it normal that in the FW Logs is sometimes a zone entry and sometimes not? The FW should in any case know what zone the paket comes from/to.
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • What do you use to store logs?

    twister5800
    twister5800
    Hi all, UTM had a brilliant logging system, but Sophos Firewall do not log many days behind, which is of no use, because we often need to go further back. Sophos Central logging we also find lacking a lot, ex. dropped packets are not logged (But maybe…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • An allow firewall rule creating many denied logs, drppkt shows nothing

    LHerzog
    LHerzog
    I notice many firewall denied firewall logs created by a rule, that is an allow rule only. Even more strange is, that the port 1027 logged is not contained in the rule. Watching the traffic with drppkt shows no blocked packets. Tcpdump shows the…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Finding SIP traffic in logviewer - how?

    rfcat_vk
    rfcat_vk
    Hi folks, I am investigating why one of my VoIP phones has failed. I have searched logviewer and its many sub-menus and not able to find any SIP traffic (UDP port 5060) or even using the ATA's IP address. Please advise how I find the SIP traffic?…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Logging: TLS Inspection log subtype = is not allowed - is showing only allowed traffic

    LHerzog
    LHerzog
    I do not understand why this happens. I noticed it when I was in firewall log and build a filter like this: It does what it should do: If I then switch the log to TLS Inspection, it shows me only allowed traffic. I know that this filter "allowed…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Convert of firewall rule export

    support support16
    support support16
    Hi, is it somehow possible to convert FirewallRule XML export from XG or XGS to some readable form for example to Excel with all needed items like list of all used source, destination networks etc. We need to convert XML to some sort of table form for…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Confused rule id and broken WAF rule.

    Michal Talman CZ
    Michal Talman CZ
    Hi, I'm having trouble with the WAF, XGS 2300 v19.5.1 I add the webserver web .xxx.xxx - it has policy ID 129 . But if I go to web .xxx.xxx in the log it shows that web.xxx.xxx has policy ID 43 . I get a 503 error But the policy ID 43 is spsluzba.xxx…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Central Reporting - is it really working?

    m@x
    m@x
    I keep hearing about the Central Reporting and how all the detailed logging is available through it, which has plenty of data points and filters. We are subscribed to Xstream Protection, which includes Central Orchestration, which includes 30 days of…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Message: Reports disk Usage reached 91% exceeding the higher watermark of 90%

    ciwan
    ciwan
    Hi We're receiving notification almost every day that is stating Message: Reports disk Usage reached 91% exceeding the higher watermark of 90% But when I ssh to it, it shows me 86%. I receive multiple emails in a same day. …
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Firewall logs - where?

    m@x
    m@x
    Log Viewer > Firewall goes back by 10 days or so. I need to retrieve Firewall logs for a period of 2 weeks starting 20 days ago. I've learned that XG(S) do not store log files for Firewall rules. From other posts I've also learned that I should use…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Reporting on Peak Concurrent Users

    ptho
    ptho
    Hi Sophos, I'd like to generate a view and report on how many users are concurrently connected to the Sophos Appliances in operation so that we can spec for a replacement unit. IS there such a feature available? We are running SFOS 19.5. We…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos XGS Firewall: Count of dropped sessions on WAN interface

    Harald Harbauer
    Harald Harbauer
    Hello, are there any options to see the count of the dropped sessions on the WAN interface over a time period? best regards Harald
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Clearing Zero-Day Protection log

    BruceGiles
    BruceGiles
    Running SFOS 19.5.2 MR-2 on an XG310. In the Zero-day protection section of the Control Center, it shows 0 Recent, 274 Incidents, 330 Scanned. When I click on that, it goes to the Zero-day protection logs, and I get two pages containing a total of 38…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • View related content throughout Sophos Firewall
  • More
  • Cancel
<>