This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Missing bulk operations in XG

Ever since I started using Sophos XG two years ago, I have been baffled by the fact that the list views in Email Log and SMTP Quarantine can only display 20 records per page with no possibility to adjust this setting.

I find it it remarkable that this has yet to be fixed in spite of the fact that several community questions prove that users are having significant problems as a result of this flaw. Especially since a "fix" would be very simple, as far as I can tell.

In my case which is probably only a moderate problem, I have around 300 pages of old spam/malware mails in SMTP Quarantine, and want to delete them. I think this ought to be possible with around three clicks, once I have clicked myself onto the SMTP Quarantine page.

Something like

1) select date range

2) select all, and

3) click delete

But instead, it requires 300*2 clicks meaning I have to set aside most of the morning to accomplish this simple task.

Other administrators, I imagine, probably have thousands and thousands of pages to click through. This design therefore costs companies hundreds of unnecessary man hours. And this is probably not the kind of tasks you assign to the intern, so this means that some of the most knowledgeable and productive employees are forced to spend their time clicking through hundreds of pages each consisting of 20 spam mails. I know that some countries are trying to design their labor markets to increase demand for educated workers, but this doesn't strike me as the most productive method to achieving this goal.

If Sophos were to make it possible for administrators to adjust the number of displayed items per page, this would reduce my administration time on the device with probably a half, and that would be the least meaningful half of the time spent. For admins at larger companies, I imagine it would be reduce even larger portions of their time.

If Sophos want to make the administration work even more effective and meaningful, I would further suggest allowing more flexible searches.

For instance when I, as an admin, am looking at thousands of mails that are caught in the spam filter, I would like to be able to gather some useful knowledge from the data, and make use of it in the future. If for example one or two domains are the origin of half of the spam emails we get, I would like to add these domains to the list of rejected senders, saving myself from spending unnecessary time on them in the future. But there is - as far as I know - no method in Sophos XG for me to extract sender domains, count them and see a sorted result. Instead I just have to click my way through hundreds of pages and see if I can recognize some pattern. Again, the data is right there in front of my nose, but instead of applying normal information science tools to quickly and consistently obtain useful knowledge from the data, I have to spend large amounts of time and possibly find something useful, and possibly not. Again, the basic functionality is there, but no regard what so ever seems to have been taken to make admins able to be productive and free them from pointless clicking for many hours.

As an absolute minimum, I would say it has be possible to delete all spam mails from a specific sender address or domain. There are examples of Sophos XG users receiving thousands of spam mails from one single address, and with the current Sophos XG firmware, this immediately occupies many hours of admin time, whereas simple usual web page functionality would reduce it to a couple of clicks.

I have discussed these issues with our local dealer, but should there be some setting or function which I have missed, I would appreciate feedback telling me so.



This thread was automatically locked due to age.
Parents
  • Sophos XG is a CLI device with GUI to perform selected tasks.  At the pace things improve it will remain as such for a predictable future.  I mean 5 years at least.

    Meanwhile, learn CLI (all of them. Firewall, Mail MTA, et.c.) ... or die.

    Paul Jr

Reply
  • Sophos XG is a CLI device with GUI to perform selected tasks.  At the pace things improve it will remain as such for a predictable future.  I mean 5 years at least.

    Meanwhile, learn CLI (all of them. Firewall, Mail MTA, et.c.) ... or die.

    Paul Jr

Children
  • Thanks, Paul Jr. I have tried to follow your advice and gotten myself acquainted with the CLI.

    However, I am having a difficult time coming up with useful commands for tasks such as the ones mentioned above.

    For instance, do you have any idea how I can delete all quarantined mails from a specific sender?

    Deleting everything from quarantine can (as far as I have been able to find out) be done by deleting everything in the folders in /var/quarantine/ .. but the contents of the folders do not seem to match the content of my SMTP quarantine in the XG web interface, so I thought it would be too risky to just delete everything and see what happens.

    The Sophos CLI manuals I have found seem to be quite detailed around how to perform simple administrative tasks such as add user, change password and so on, but say nothing about email.

    In terms of a more email-specific CLI, it appears that Sophos XG uses the Exim Mail Transfer Agent, but the Exim documentation doesn't seem to contain any examples or explanations as to how to perform searches in quarantine or how to delete quarantined emails.

    I feel like I am learning a lot, but at the same time, relevant information seems to be very difficult to find. If you have any useful tips or resources, please let me know.

  • Hello

    I wish I could help you, unfortunately, I have quit doing anything mail related with Sophos.  It was consuming many times the cost of buying Symantec Brigthmail when adding up hours fixing/debugging/learning.

    So I have abandoned Sophos Mail Virtual appliance altogether.  And Email MTA on XG before Sophos migrated to Exim.  I do not intent to even try Exim at all.

    Brigthmail reporting is light-years ahead, with the additional benefit of being a true set-and-forget solution.  Early next year, I will abandon Sophos SEC as well and go back to Symantec End Point.

    We are in 2019, and CLI should have been dead decades ago.

    For now, we may keep Sophos appliances for basic firewall tasks.  The notion of all-in-one UTM appliance is nothing more than a pipe dream, and a failure.  And anyway, MTAs, WEB filtering, et.c. are all moving to the cloud.  So UTMs are slowly becoming irrelevant.  XG is no different, and is also cruising on the fast lane to become a not-enough-and-too-late solution.

    They should have pimp-up UTM, cause as of now, XG was a strategic mistake.

    Paul Jr