Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

File Integrity Monitoring

Hi All,

 

We have rolled out file integrity monitoring. My question is can someone share with me how they are reviewing these events daily? We have a central log monitor, but since Sophos does not write any detail to the event's general message, only in the detail, it is of no use to us. My only option at this time is to manually review each server's event log daily which is not practical. There are no events in Sophos Central other than to indicate monitoring status. So really, at this point, it is only a tool we can use when researching an event that was detected by other means and not something we can use for proactive monitoring. Thanks.



This thread was automatically locked due to age.
Parents Reply
  • Hi  

    I just want to confirm that you are referring to any third party tool which can help you to maintain the logs from all the servers in your environment as your current tool is failing.

    Because it looks like you want to know details about how FIM works if we follow your first question.

Children
No Data