How to open application usage monitoring?
You can open this view from the application menu: Menu -> Monitoring -> Applications. It is the main place for checking how work with programs looked on monitored computers: which applications were in the foreground, how long the user worked actively, how much time was idle, and how often keyboard and mouse interactions appeared.
Use this view when you want to analyze the real distribution of work between applications, compare employee activity on computers, review the share of productive and unproductive programs, or detect unusual switching between windows. Application usage monitoring is not an installed software inventory. It describes program behavior during the workday and shows which applications actually appeared in user activity.
The view consists of an analytics panel and a daily records table. The panel collects metrics, rankings, trends, comparisons, anomalies, hourly presence and data quality. In the table, every entry is a daily monitoring record for a specific computer. Clicking such an entry opens details for the selected day, workstation and related employee, aggregated by application, process, window title, active time, idle time and productivity category.
Daily table in application work monitoring
The table is a quick list of days in which the agent saved application usage on a computer. By default, it shows values useful for the first reading of the day: active time, idle time, the number of detected applications and the program that dominated usage.
The key columns visible immediately are:
- Active Time - time in which applications were connected with active user work.
- Idle Time - time in which an application stayed in the day context, but without active interactions.
- Applications - the number of unique programs recognized in the record.
- Most Used Application - the application with the highest share in that summary.
After expanding columns, you can also check Foreground Time, Most Active Application, Application Category, Productivity Category, Keyboard Count, Mouse Click Count, Segments, Foreground Opens, Last Window Title and Executable Path. These fields help distinguish a stable day spent in a few programs from a day filled with short switches between applications.
The search can use date, agent, computer, Windows user, active hours, application names, window titles, executable paths, productivity category and detail text. With that, you can locate a specific program even when you remember only part of the window title or process name.
Analytics panel in application activity monitoring
The analytics panel summarizes application usage for the selected date range. You can switch between a day, week, month or custom period, and count values as Total or Daily Average. Daily average is especially useful when you compare periods with different numbers of workdays or want to see a typical day instead of the combined total.
The main panel metrics are:
- Foreground Time - total time of applications visible as the active window.
- Active Time - work time connected with user interactions.
- Idle Time - time without active work in the context of observed applications.
- Activity - percentage share of active time against active and idle time.
- Applications - the number of programs recognized in the analyzed period.
- Keyboard and Mouse Clicks - the number of recorded interactions.
- Interactions during active hours - interaction pace calculated against active work time.
It is worth reading these metrics together. High Foreground Time with low Activity can indicate an application window left open, while a high Interactions during active hours value with short segments may point to work with many quick switches.
Rankings in most-used application monitoring
Rankings show which applications, computers and employees have the largest share of work time. In this view, a ranking should not be read as a simple assessment of work quality. It is more a concentration map: it shows where time, idle time, activity and foreground work accumulate.
In the panel you can switch between, among others:
- Top Active Applications, Top Idle Applications and Top Foreground Applications.
- Least Active Applications, Least Idle Applications and Least Foreground Applications.
- Top Active Computers, Top Idle Computers and similar employee rankings.
- Productivity Categories and Application categories, which show time share by classification.
Start with applications, then move to computers and employees. If one application has a lot of idle time, check record details and window titles. If many applications have short active time, context switching may matter more than the program name itself.
Trends in application time monitoring
Trends show how application usage changed day by day. Available series include Foreground Time, Active Time, Idle Time, Activity, Applications, Interactions, Computers and Employees. This helps you separate growth in the number of used programs from growth in time spent in the same tools.
When working with trends, pay attention to:
- days where Idle Time grows without a similar increase in activity,
- growth in Applications, because it can mean more fragmented work,
- changes in Activity after adjusting the work schedule or monitoring profile,
- differences between Computers and Employees, which show whether the analysis includes shared workstations or users working on several computers.
The Hourly Presence chart presents the share of days from the selected range in which a given local hour contained application activity. Do not treat it as the sum of work time in that hour. It is an occurrence signal, useful for checking the rhythm of the day, but not for accounting minutes.
Comparisons in application activity change monitoring
The comparisons tab compares the current range with the previous period and shows which metrics increased or decreased. In application monitoring, this is very useful after organizational changes, new tool rollouts, a different remote work rhythm or a change in productivity classification rules.
The most useful insight comes from comparing several values at once:
- an increase in Active Time with a stable number of applications can mean longer work in the same tools,
- an increase in Idle Time should be read together with hourly presence and application details,
- an increase in Applications can point to a broader set of programs or more fragmented work,
- a change in Interactions during active hours helps show whether the user worked more intensively or only kept applications open longer,
- an increase in Computers or Employees means the comparison covers a wider data scope.
If the difference is large, do not stop at the change percentage. Open application rankings, then details for a selected record. Only the process name, window title and usage share usually show whether the change comes from real work, an application left open or a new pattern of using tools.
Anomalies in application behavior monitoring
Anomalies help catch situations that can look like an ordinary day in the table, but are unusual compared with the previous period. The system checks active time and idle time, switching between applications, new programs with a high share and unusual interaction pace.
In this view, the especially important anomalies are:
- Idle time increased significantly - when the current period has clearly more idle time than the baseline period.
- Active time decreased significantly - when active work dropped below the comparison threshold.
- High application context switching - when the number of segments is high in relation to foreground time.
- Average application segment is very short - when work consists of many very short fragments.
- New application has a high usage share - when a program was absent before and now takes a significant part of time.
- Unproductive applications have a high usage share - when classification shows a large share of the unproductive category.
- Interaction rate changed significantly - when keyboard and mouse activity per active hour differs from the comparison.
For productivity-related anomalies, first check classification rules, because the result depends on how the organization labels applications. For context-switching anomalies, details explain the most: the application list, processes, segment times and window titles.
Record details in used application monitoring
After selecting a record, the application shows applications aggregated for one day and one computer. Details let you see which programs actually created the result visible in the table and how time, interactions and categories were distributed.
In details, check especially:
- Application, Process and Executable Path, which identify the program.
- Last Window Title, which helps understand the work context in the application.
- Foreground Time, Active Time, Idle Time and Usage Share, the key time values.
- Keyboard, Mouse Clicks, Focus Switches and Foreground Opens, which describe how the program was used.
- First Seen, Last Seen and Active Hours, the time frame of application presence.
- Application Category, Productivity Category and Windows User, which support organizational interpretation.
In this view, hourly filtering does not split time or counters into individual hours. The system records whether activity was present in an hour, but it does not assign exact application counters to that hour. Details should therefore be read as a daily application usage summary, not an hourly log for each program.
Data quality in user application monitoring
Data quality shows whether the daily summary has valid application details. This matters because record counters can exist even when the application list is still being aggregated, has incomplete items or does not match the daily total.
In the panel you may see:
- Details Coverage - what part of records has available application details.
- Records Without Details - days where application activity is visible, but the item list is missing.
- Live Partial - current-day records whose aggregation may still be running.
- Historical Open Records - older days that were not closed correctly.
- Invalid Details - cases where detail data has an invalid structure.
- Missing Data Days - days from the selected range where application usage data did not arrive.
If the warning concerns the current day, it is often enough to wait for aggregation to finish. If the problem concerns closed days, check the agent state, the Process Event Monitoring setting, process exclusions and whether the agent local queue correctly sent data to the backend.
Application usage monitoring settings
The Applications view uses settings stored in Monitoring Profiles. Configuration is sent to the agent and starts working after the computer receives it. For this manual page, the most important options are only the editable ones that affect collecting application data or interpreting it in the panel.
In the profile, check:
- Activity Monitoring - general user activity collection, needed for meaningful interpretation of active and idle time.
- Process Event Monitoring - enables process data used by the Applications view; without it, the agent does not have full material for daily application summaries.
- Excluded Process Names - a list of processes that should not be treated as ordinary user applications; a single entry is described as Process Name.
- Productivity Classification - allows application usage to be assigned to productivity categories.
- Productivity Rules - rules that classify domains, applications, processes or window titles.
In a single productivity rule, Name, Value, Match Type and Category matter. Available match types include Domain contains, Application contains, Process name and Window title contains. The category can be set as Productive, Neutral or Unproductive. After changing rules, return to this view after the next monitoring day and check whether Productivity Categories and anomalies related to unproductive applications show the expected picture of work.
