๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

Sophos Cases by Device

Review Sophos investigation cases for each computer and firewall, with severity, status and the analyst's verdict side by side.

Where to find it
Cloud/SAAS โ€บ Sophos โ€บ Incidents/Cases (also opened from the Cases counts on Sophos Computers and Sophos Firewalls)
Who can use it
Anyone who can see the page
Plan
Sophos integration
For
Everyone

What the page is for

Sophos Central opens a case when it investigates suspicious activity. This page lists those cases for your linked Sophos organizations, as of the last Sophos sync, and ties each one to the computer or firewall involved.

Each row shows the case ID, organization, device, device type (endpoint or firewall), severity, status, verdict, title, and when the case was created and last updated. Where the device matches a computer in Lavawall, its name links to the Lavawall device page.

It is the page behind the Sophos Incidents/Cases menu item, and it opens already filtered when you click a Cases count on Sophos Computers or Sophos Firewalls.

What you see

The Sophos Cases by Device page, with the filters, search and buttons and cases table numbered 1 to 3.
The Sophos Cases by Device page. Numbers match the list below.
  1. Filters: Organization, Severity, Status, Device and Device Type multi-select boxes.
  2. Search and buttons: Search all fields, Apply and Reset.
  3. Cases table: Case ID, Organization, Device, Device Type, Severity, Status, Verdict, Title, Created and Updated, each sortable.

How to review open cases

  1. In Status, choose action required (and investigating if present).
  2. Optionally choose critical and high in Severity.
  3. Click Apply. Sort by Updated to see the most recent activity first.

How to see every case for one computer or firewall

  1. Choose the device in Device, or type its name in Search all fields.
  2. To see only firewalls or only computers, choose firewall or endpoint in Device Type.
  3. Click Apply.

How to sort and reset

  1. Click any column heading to sort; click again to reverse it. Updated newest-first is the default.
  2. Click Reset to clear every filter.

Tips

  • Severity badges: critical and high are red, medium is amber, low is blue, informational is grey.
  • Status badges: action required is amber, investigating is blue, on hold is grey, resolved is green.
  • Verdict badges: False positive and True positive: benign are green, Inconclusive is blue, True positive is amber, True positive: malicious is red.
  • The Organization filter starts on the Sophos organizations linked to the company selected at the top of the console.
  • Click a device name to open its Lavawall device page and check patches, software and recent activity.

Troubleshooting

  • No cases are listed. Check that a Sophos sync has run and that the Sophos organization is linked to the selected company on Sophos Summary and Setup. Clear the filters with Reset.
  • A device shows an ID instead of a name. Sophos did not report a matching computer or firewall for that case in the last sync.
  • Only some cases appear. The table shows up to 1,000 cases, and cases without a title are left out. Narrow the filters.

Task guides that use this page

Still need help?

Search the support centre, or contact our support team and tell us which page you were on.

Names, companies, devices and figures in the pictures are examples. Other product and company names are trademarks of their respective owners.