Sophos Reporter Release Notes
Sophos Reporter 3.0.1.32 (2020-03-11)
  • Fixed an issue that may prevent Search Term Alerts from working after the alerts are edited. If you’re experiencing this issue, edit your Search Term alert, and make sure the filter for Site Resource with the values /s and /su are set to ‘Not equal to’. There was an issue where this portion of the filter would be set to ‘Equal to’ if the alert was edited and saved, preventing the alert from working correctly.
  • Fixed issue that may result in out of memory issues after startup when the data retention policy attempts to calculate the size of old / closed indexes.
  • Elasticsearch no longer writes out enormous heap dump files when it runs out of memory. Any existing heap dump files will be deleted when disk space gets low.
  • Added Source Hosts and MACs section to the IT and Network security report.
  • Installation now cleans up Elasticsearch package extraction temporary files even if the extract fails.
  • Fixed issue in Alert Settings where the Alert Evidence Config Table sets example data to ‘User’ after the table is loaded.

Sophos Reporter 3.0.1.31 (2020-02-11)
  • Renamed the Context Match, Context Prefix and Context Suffix fields to Content Match, Content Prefix and Content Suffix.
  • Fixed issue where blank lines could appear in the Sites by Size (Cleaned) Widget in Overview Reports, and Top Sites Widget in the Bandwidth Dashboard.
  • Improved the logic that decides what columns are displayed in Activity Reports. Fields will no longer have their column removed when using exclude operators if there is also a filter using an include operator for the same field in the filter set.
  • Search Terms are no longer extracted from resources starting with /cortanaassist/

Sophos Reporter 3.0.1.30 (2019-12-13)
  • Fixed issue preventing the Fastvue Reporter service from starting on Server 2008 (non-R2) with certain regional settings.

Sophos Reporter 3.0.1.29 (2019-12-12)
  • Improved the extraction of Search Terms to reduce false positives.
  • Fixed issue preventing the Fastvue Reporter service from starting on systems with certain regional settings (including Portuguese).
  • Improved performance of Activity Reports.
  • Report email attachments will no longer be generated if the report contains no data.
  • Print, Export, and Share buttons are no longer available when a report does not contain data.
  • Fixed the formatting of TopX widgets in PDF exports.
  • Running in Demo Mode now populates YouTube videos, YouTube searches and other minor improvements.
  • New domain substitutes:
    • musical.ly now shows as tiktok.com.
    • spotifycdn.net now shows as spotify.com.
    • dropboxapi.com now shows as dropbox.com.
    • d3cv4a9a9wh0bt.cloudfront.net now shows as atlassian.com
    • *.nflxso.net now shows as netflix.com

Sophos Reporter 3.0.1.28 (2019-11-12)
  • Fixed further issues with Data Retention that may prevent old data from being deleted from disk.
  • Fixed report errors that may occur when reporting on large date ranges.
  • Fixed issue where the Largest Download shown on the Overview Dashboard may not match the Largest Download shown on the Bandwidth Dashboard. 
  • Improved the performance of the Dashboard queries. 
  • When importing syslog data via TCP, any "Connection Forcibly Closed" issues are automatically removed when the syslog connection is re-established.
  • If email settings are not configured, a prompt is now shown under the email options in Settings | Reports | Scheduled Report.
  • Improved Demo Data. YouTube URLs no longer show unknown:// as the URL scheme.

Download the latest version from the Fastvue Sophos Reporter Download Page. Join the Fastvue Product Testing program to access Fastvue’s latest pre-release products.


Sophos Reporter 3.0.1.27 (2019-11-01)
  • Reports can now be exported, shared and scheduled as PDF or CSV, and attached to report notification emails.
    Sharing a PDF Report via Email
  • When exporting, sharing or scheduling Activity Reports as PDF or CSV, you get the option to export the report with session rows collapsed or expanded.
    Share Activity Report PDF via Email
     
  • Improved the format of CSV exports. 
  • Fixed issue preventing the 'Retry Report' button that gets displayed when viewing a failed report from working.

Download the latest version from the Fastvue Sophos Reporter Download Page. Join the Fastvue Product Testing program to access Fastvue’s latest pre-release products.


Sophos Reporter 3.0.1.26 (2019-10-28)
  • Fixed a major issue where data exceeding the retention policy was not removed if was older than 32 days.
  • Added 'Users' to the Network section in IT and Network Security.
  • Improved Search Terms field to remove values that are not actual searches.
  • Fixed issues preventing the ability to cancel in-progress Overview Reports.
  • Adjusted the columns returned when filtering Activity Reports by the newly added Override fields (added in v3.0.1.25).
  • Activity Reports now limit the individual URLs returned within each browsing session's inner table to 2000 rows, improving performance and general readability.
  • Added APIs for retrieving Elasticsearch index details (Database.ElasticIndexInfo) and requesting a reindex (Database.ElasticReindex(index)) in the case that its field mapping becomes invalid.
  • Improved diagnostic logging. Added metrics for System CPU, System RAM, and System Disk to show system-wide resource utilisation.

Sophos Reporter 3.0.1.25 (2019-10-08)
  • Added support for Sophos XG's 'Web Filter Override' fields. Override Token, Override Name and Override Authorizer are now available to use in Alerts and Report filters. To configure Web Filter Override policies in Sophos XG see https://community.sophos.com/kb/en-us/133116.
  • Excluding values from an Activity Report no longer adds the excluded field as a column.
  • Saving Productivity Settings with an active browser translation plugin no longer voids Productivity Settings.
  • Colours in the Pie and Line charts now match on the Overview Dashboard
  • Alert evidence sample data is now populated when adding a new evidence column.

Sophos Reporter 3.0.1.24 (2019-08-27)
  • Added support for Sophos XG's 'Context-aware Keyword Filtering' fields. Context Match, Context Prefix and Context Suffix fields are now available to use in Alerts and Report filters.
  • Added support for Sophos XG's 'Direction' field (Values contain IN or OUT). You can now use this field in Alerts and Report filters.
  • Fixed minor UI display issues.

Sophos Reporter 3.0.1.23 (2019-08-06)
  • Fixed issue where Fastvue Reporter's data retention policy could prevent or slow the service from shutting down when it is deleting multiple indexes.
  • Fixed issue where the database status toggles between Operational/Failure status when running reports on a large number of old dates (older than 32 days).
  • IT Overview Widgets now show the 'number of blocks' for the top blocked site, top blocked category and top threat instead of size.
  • The Users by Size and Departments by Size widgets now excludes non-web traffic. Non-web traffic was being displayed as 'Series 1' in the charts in these widgets.
  • Failed Traffic widget in the Blocked Traffic sections now populates correctly when using Sophos XG data.
  • Fixed issues in URL parsing when the logged hostname also contains a port.
  • Changing data location via the UI or API now rejects the request if the path is the same, is a subfolder of the original path, or the new path cannot be written to.
  • Fixed areas of the user interface that were not working when installed on non-English variants of Windows Server. For example, viewing Import Issues was not working when installed on Turkish Windows. All ID-based lookups now use case-insensitive invariant culture string comparisons.
  • The installer now detects 32-bit operating systems and blocks installation.
  • Updated 3rd party libraries and licenses in Settings | About.