Knowledge Hub · Security

How long are Sophos firewall logs kept in FirstNet's managed firewall service?

Hosted Firewall & Network Security · Answered by FirstNet Technology Services

Short answer

With Standard Protection, logs are kept on the firewall for seven days with basic reporting in Sophos Central. Xstream Protection adds Central Firewall Reporting Advanced, with 30-day cloud log retention and multi-firewall reporting.

In detail

If you need logs for longer:

  • Sophos MDR: logs can be retained in the Sophos MDR data lake, alongside 24/7 detection and response
  • Your SIEM: logs can be forwarded via syslog to a SIEM you manage
  • Sophos NG-SIEM: available for compliance reporting and longer log retention at enterprise scale

All firewalls, on site or hosted by FirstNet, log to Sophos Central, and all changes are audit-traceable through Sophos Central audit logs.

Retention requirements often come from auditors, regulators or cyber insurers, so check what period you need to evidence before choosing a bundle or retention option. The retention approach and any integration are confirmed during the design phase, so they can be built into the service from day one rather than added after an audit finding.

Source: FirstNet Hosted Firewall & Network Security service page →

Didn’t answer your question?

Call