• Is Sophos CPU history recorded in Data Lake?

    PK1
    PK1
    Is Sophos CPU history recorded in Data Lake?
    • 1 month ago
    • Sophos Endpoint
    • Discussions
  • Protected devices/users

    Josefina Frutos
    Josefina Frutos
    Hi! I wanted to know if there is a way to download the list of users and the serial numbers of the computers assigned to them. From what I've seen in the reports section, it doesn't allow modifying the columns. Do you know if it's possible to download…
    • 2 months ago
    • Sophos Endpoint
    • Discussions
  • Finding where the domain users group added to the remote desktop users local group

    Nandha
    Nandha
    Hi, Is there any osquery to get all the domain-joined machines where the "Domain Users" group is added to the "Remote Desktop Users" local group?
    • 3 months ago
    • Sophos Endpoint
    • Discussions
  • How can I search for a MD5 Hash with Sophos EndPoint

    Hans_Dampf
    Hans_Dampf
    I have a hash like: 6ea2c9276c122222222222f9ae2 i want to search on the clients for this hash. is there a posibility to search with Sophos EP?
    • 5 months ago
    • Sophos Endpoint
    • Discussions
  • Query for : IP/URLs accessed from Mac user or deivces

    GunjungLee
    GunjungLee
    Is there a query that can be used to see if a user or Mac device has accessed a specific IP or website?
    • 6 months ago
    • Sophos Endpoint
    • Discussions
  • Any way to query events for 'Applications and Services Logs' via Live Discover?

    iamroot
    iamroot
    Hello everyone, I understand there is a way to query for event logs in Live Discovery. From what I see, it may be limited to Windows Logs only i.e Application, Security, Setup, and System event logs. I tried querying an event id, but it pulled from…
    • Answered
    • 10 months ago
    • Sophos Endpoint
    • Discussions
  • live discovery query for: web browsing activity of MAC device

    Hemanth Kurungat
    Hemanth Kurungat
    Hi, Please let us know if there is a sql query for get all web browsing activity of user/ computer for MAC devices on sophos central. I found we have inbuilt query available for Windows as : "URLs accessed on Windows (Data Lake)". Kindly let…
    • Answered
    • 10 months ago
    • Sophos Endpoint
    • Discussions
  • Retrieve more information of client devices?

    Vincent Luckmann
    Vincent Luckmann
    Hello dear Sophos Community, we have some old devices in our company and I noticed that the sophos agent collects data like Processor structure and Operating System but now my question is; Can I get Sophos to collect more information than this from…
    • Answered
    • 11 months ago
    • Sophos Endpoint
    • Discussions
  • Datalake Query windows_programs with some empty "name" columns

    Philippe Hirzel
    Philippe Hirzel
    I am playing around with the XDR Datalake. The goal is to use the XDR Datalake for our inventory. So we do not have manually update it. I can get all installed software from the Datalake thanks to the query "windows_programs". However in this query…
    • 11 months ago
    • Sophos Endpoint
    • Discussions
  • Display Installed Programs on Computers

    Onur Akcay
    Onur Akcay
    Hello, I want to display installed programs on my users' computers. I wonder if i can do that with Sophos. Thanks,
    • Answered
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Core Agent report Sophos Central

    Patryk Gryze
    Patryk Gryze
    Hi, How to generate a report of Core Agent version of all devices? Excel or CSV, do not mind
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Custom Query Intermittent Results

    Lee Fellows
    Lee Fellows
    We have created a custom query to allow us to find specific file names and path on any system within our tenant. SELECT file, path FROM sophos_file_journal WHERE file LIKE '$$Filename$$'; This is very temperamental, as it will sometimes return a result…
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Need help in building OS Query for Finding SHA1 andSHA256

    Jenil Sadrani
    Jenil Sadrani
    Hello All, I have been trying to create custom queries in Sophos Central for finding IoCs (SHA1 and SHA256). Can you please help me build query for the same? Regards, Jenil
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Sophos XDR Technical Demo (23 minutes)

    Andrzej Kozlowski
    Andrzej Kozlowski
    I upgraded my subs to XDR and looked to following video: https://vimeo.com/519661823 Unfortunately I do not see tables mentioned there like: Data Lake hydration queries query result List all EP and XG FW Tables Windows programs Inventory search…
    • Answered
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Scheduled query - recommendation

    Andrzej Kozlowski
    Andrzej Kozlowski
    I have mixed Mac and Windows environment. So far I scheduled weekly two queries: Pending macOS updates Data Lake Pending Windows updates Data Lake Do you have any other recommendation what makes sense to run using the schedule ?
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Detections Many Level 4 messages

    Andrzej Kozlowski
    Andrzej Kozlowski
    Hello, Just upgraded my license to XDR and now under detections I see many level 4 warnings like: SRP path rules missing. Secure boot supported but not enabled. DEP is not Admin Opt-out or Always-on. Applications with special compatibility…
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Intercep C XDR: Manage On-disk Data Storage

    IT BLD
    IT BLD
    Hello Community, we are testing Endpoint Protection in Sophos Central. The Tech Specs contains the Features "Sophos Data Lake Cloud Storage" and "On-disk Data Storage". I found "Upload to the Data Lake" in the Global Settings. But I do not find "On…
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Users who have administrative access

    Andre Soares
    Andre Soares
    Hello everybody. is there any query that checks all users with administrative privileges on the network? Thanks
    • Answered
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Checking the status of OS updates via Sophos Central

    James Harding
    James Harding
    On Sophos Central is there a way to check devices for the status of OS updates to ensure they are up to date? Windows MacOS Linux
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Checking what other applications are installed on a device via Sophos Central?

    James Harding
    James Harding
    Is there a way to check what applications are installed on a device and if these are up to date via Sophos Central?
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • how to find and delete IOC by using XDR

    Ahmad
    Ahmad
    i have intercept-X with XDR installed i want to see that if any particular IOC is present or not??? if present then how can i delete it?? please guide.
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • How to get list of machines whose core agent is not up to date

    RMMSD
    RMMSD
    How to get list of machines whose core agent is not up to date or how to get core agent list completely for all sub estates
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Sophos Endpoint

    enemy1337
    enemy1337
    Guys, I have a doubt. there is no more sophos product for endpoint with EDR? XDR only?
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • How to list the installed applications in end devices

    IT Security Operations
    IT Security Operations
    How to list all installed applications in the windows end devices/Clients using sophos Threat Analysis Center.
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Sophos Central -Capacidad para monitorear recursos y obtener datos de endpoints

    Arturo Carrillo
    Arturo Carrillo
    Buen día. Espero me puedan ayudar con esta duda. ¿Hay manera de que desde Sophos Central pueda obtener información de un endpoint como marca, modelo, número de serie, sistema y algunas características del hardware del endpoint? En caso de que no…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • View related content throughout Sophos Endpoint
  • More
  • Cancel
>