Hallo,
wie kann ich das Ereignisprotokoll auf dem Endpoint löschen, oder die Dauer der Speicherung einstellen.
Beste Grüße
Marcel
This thread was automatically locked due to age.
Hallo,
wie kann ich das Ereignisprotokoll auf dem Endpoint löschen, oder die Dauer der Speicherung einstellen.
Beste Grüße
Marcel
Hallo Marcel Hoffmann
To reset the events database events.db file you need to do the following:
1. Disable Tamper Protection
2. Under Windows Services (services.msc), Stop Sophos Health Service
3. Go to C:\ProgramData\Sophos\Health\Event Store\Database and rename the file events.db to events.orig.
4. Restart Sophos Health Service.
5. Open the Task Manager and end the process Sophos Endpoint User Interface.
6. Launch a new Sophos Endpoint user interface by clicking the file C:\Program Files\Sophos\Sophos UI\Sophos UI.exe and verify that its status is green and the event count is 0.
7. Enable Tamper Protection again.
If you need the steps for a Mac, please let us know.
I don't think you can change how far back the events are logged. You can submit this as a product enhancement request or vote if one already exists at https://ideas.sophos.com.
Thanks,
Hi LKramer
Please start with the steps in this KB: Sophos Central Endpoint: How to reset the detection count in Mac endpoints
If that does not help you, follow the steps below:
Only perform these steps if the Reset Summary did not work.
events.db
to events_old.db
. 0
, respectively.