This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

AUDIT LOGS FOR DELETED RECORD

Hi

I'm using Sophos XG version SFOS 17.5.5 MR-5 and need to get users accessing the Internet in the past 30 days, however, when I checked in specific days under custom report there are no records found.

Please let me know

1. how do I get audit for user deleted the logs if any

2. How do I track what happens for the missing record

3. Will the missing record be recovered

Thanks in advance for your support.



This thread was automatically locked due to age.
Parents Reply Children
  • Thanks, Vishal

    We have preserved a historical log for web traffic for a period of three months but funny enough we cannot see logs for some of the days in last month which is within the preserved log history. That is why I need assistance on seeing the audit logs maybe someone has deleted the logs. please assist.

  • Hi  

    Is device running in HA Active Passive setup? If yes then check the reports on another appliance for the missing days to confirm if another device containing reports for those days. 

    If it is not in HA setup and only stand alone device then this required further advance logs checking and log files.For that you may raise a support case to investigate the issue further.

    As you are running with older version there could be chances appliance may affected with some report related issue as well which is fixed in latest version.

    Example : NC-46780 [Logging Framework] Reports not being generated when Email Notification feature is enabled

    Fixed in MR-8.

    https://community.sophos.com/products/xg-firewall/b/blog/posts/sfos-17-5-mr8-released

  • Thanks Vishal for your continuous support, unfortunately, I'm not running in an HA active Passive setup and after this, I will definitely upgrade to the current version.