This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Enterprise Console - auditing firewall blocks

I am using the Enterprise Console 5.1. What is the best way to browse the Sophos log files for machines that I manage? Or better yet, is there a console dashboard or report that will show me details on all the blocked communication attempts on a particular machine or machines? We're just rolling out Sophos, and I want to watch my firewall events to make sure I'm only blocking what I want to block on various machines. I have found the report that shows me blocks, but it's woefully inadequate for driving further action. I just get a block time, the blocked application, and system name. I really want a direction, as well. When I'm actually on a managed system and pull up the Sophos console, it's got a nice interface to view activity/logs. Where is that on the Enterprise Console? Thanks!
:29491


This thread was automatically locked due to age.
Parents
  • Hello Neon,

    as you say report I assume these are what you looked at. Far better for what you want is the Event Viewer - from the View menu. It has more details and you can also create rules from the events.

    HTH

    Christian

    :29499
Reply
  • Hello Neon,

    as you say report I assume these are what you looked at. Far better for what you want is the Event Viewer - from the View menu. It has more details and you can also create rules from the events.

    HTH

    Christian

    :29499
Children
No Data