How to open monitoring for hardware audit?

Open the view from the application menu: Menu -> Monitoring -> Audit - hardware. This is not a screen for continuous tracking of user work, but a daily snapshot of a computer’s hardware configuration. The agent collects device state and saves automatic hardware inventory: Hardware Items, Hardware Categories, Hardware Manufacturers, Source Classes, Processors, Memory Modules, Physical Disks, Logical Disks, Network Adapters, Video Controllers, Monitors and Input Devices.

Use this view when you want to check the real state of company computers, whether RAM changed, whether disks were added or removed, how much free space remains on logical disks or which models and operating systems are currently visible in the environment. Hardware audit monitoring is especially useful for periodic IT asset checks, preparing hardware replacement, analysis after computer repair and detecting changes that did not pass through formal inventory.

The view has an Analytics Panel, a table of daily snapshots and a details area. The panel is described in the following sections because, for hardware audit, it is important that current metrics are based on the latest record of each computer in the selected range. One table row means one audit day for one computer. After opening a row, the application shows hardware details from that snapshot for the selected device and employee, together with category, name, manufacturer, model, serial number, size and free space where those values exist.


Daily table in monitoring hardware inventory

The table lets you quickly review hardware state by computer and day. Read it as the result of a daily audit, not as an event list. If the same machine appears on several days, each record shows a separate state collected by the agent.

The most important table columns include:

  • Hardware Items - the total number of positions detected in the snapshot.
  • Hardware Category Count - how many hardware groups were recognized.
  • Total Physical Memory - the RAM total visible in the audit.
  • Total Disk Size - capacity of physical disks detected on the computer.
  • Total Logical Disk Free Space - space available on partitions and volumes.
  • Logical Disk Free Percent - a quick indicator of disk-full risk.

The record also contains the audited computer name, domain, manufacturer, model, serial number, operating system, OS version, architecture and processor name. The search field checks date, agent, computer, Windows user, active hours, device data, manufacturers, models, serial numbers, operating system and technical JSON detail content.


Analytics panel in monitoring daily hardware snapshots

The analytics panel gathers records from the selected range, but builds the current hardware picture from the latest snapshot of each computer. Because of that, Hardware Items, Total Physical Memory, Total Disk Size and Total Logical Disk Free Space show the current environment state instead of repeatedly adding the same devices from consecutive days.

In the panel, it is worth starting with a few metrics:

  • Hardware Items - the scale of the detected inventory.
  • Total Physical Memory - RAM resources visible in the latest snapshots.
  • Total Disk Size - the sum of physical disk capacity.
  • Total Logical Disk Free Space - the amount of space available for the system and users.
  • Processors, Video Controllers and Network Adapters - basic hardware component groups.
  • Computers and Employees - the scope of devices and people linked with records.

In practice, compare Hardware Items with Hardware Category Count and Source Classes. If values are low or typical categories are missing, check data quality and record details first, before deciding that the computer really has an unusual configuration.


Rankings in monitoring computer configuration

Rankings organize automatic inventory so dominant models, manufacturers and device types are immediately visible. The default summary shows Hardware Categories, meaning the general division of detected items into groups such as computer, BIOS, processor, memory, disk, network, monitor or video.

The panel includes, among others:

  • Hardware Categories and Hardware Types - a general picture of which item classes the agent collected.
  • Hardware Manufacturers and Computer Models - useful for fleet standardization.
  • Operating Systems and BIOS Versions - helpful for compliance, updates and replacement planning.
  • Processors, Memory Modules and Physical Disks - the most important performance-related elements.
  • Logical Disks, Network Adapters, Video Controllers, Monitors and Input Devices - detailed component groups.
  • Computers and Employees - ranking records by detected hardware item count.

Rankings help separate standard from exceptions. If most computers share a similar model and system but one device stands out, go to details. If the Source Classes ranking is sparse, it may indicate limited WMI data or an issue with the audit scope.


Trends in monitoring hardware changes across snapshots

Trends show how daily snapshots changed over time. They are not a history of one device being connected. They are a series of states from which you can read increases or decreases in hardware items, disks, memory modules, network adapters or free space.

Available charts include Hardware Items, Processors, Video Controllers, Network Adapters, Disk Count, Logical Disk Count, Total Physical Memory, Total Disk Size, Total Logical Disk Free Space and Logical Disk Free Percent. Each point means daily aggregation of data from computers in the selected range.

When interpreting trends, watch sudden drops and jumps. A free-space decrease without disk-size change usually means space consumption, while a change in Total Disk Size may mean media replacement, adding a disk, failed reading or different hardware classification by the system.


Comparisons in monitoring hardware asset state

The comparison tab sets the current range against a baseline period. In hardware audit, this is useful for checking whether the computer fleet has the same state as before or whether noticeable differences appeared in item count, memory, disks or free space.

The most practical comparisons concern:

  • Hardware Items - show whether the number of detected positions changed across computers.
  • Processors, Disks and Logical Disks - help detect configuration change or missing data.
  • Network Adapters and Video Controllers - point to differences in detected devices.
  • Total Physical Memory - helps notice added or lost RAM.
  • Total Disk Size and Total Logical Disk Free Space - support capacity and space usage checks.
  • Logical Disk Free Percent - simplifies assessment of disk-full risk.

If the difference is large, check whether it affects many computers or one device. For a single computer, it is usually enough to open record details and compare Hardware Name, Hardware Category, Manufacturer, Model, Serial Number and Size.


Anomalies in monitoring unusual hardware changes

Anomalies in the Audit - hardware view point to situations that may mean a real configuration change, a capacity issue or an incomplete snapshot. The mechanism compares the latest state with the reference period and also checks free-space thresholds.

The panel may show these signals:

  • Hardware item count changed significantly - the computer has a clearly different number of detected positions than in the baseline period.
  • Disk capacity changed significantly - detected physical disk capacity differs from the earlier snapshot.
  • Physical memory changed significantly - RAM amount changed beyond the configured threshold.
  • Logical disk free space is low - the percentage of available space dropped below the warning or critical value.
  • Essential hardware category is missing - the latest details do not contain one of the expected categories, such as computer, BIOS, processor, memory, disk, network or operating system.

In anomaly evidence, check Current Hardware Item Count and Baseline Hardware Item Count, Current Disk Size and Baseline Disk Size, Current Physical Memory and Baseline Physical Memory, Logical Disk Free Size, Logical Disk Free Percent and Missing Hardware Category. Only after that verification decide whether it is an actual hardware change, a reading problem or a planned administrative operation.


Record details in monitoring component audit

After clicking a record, you will see daily snapshot items for one computer. Details are sorted by Hardware Category and Hardware Name, so it is easy to move from a general group to a specific component.

In details, you will find for example:

  • Hardware Name and Hardware Category, which describe the item in a readable form.
  • Hardware Type and Source Class, useful when analyzing WMI data.
  • Manufacturer, Model, Serial Number and Version, which are component identification data.
  • Size, Free Space and Free Space Percent for disks and volumes.
  • First Seen and Last Seen, which help determine when the item appeared in the record.
  • Active Hours, Device ID and technical day fields if you need to check the record source.

When analyzing, start with the category and only then move to manufacturer and serial number. If you want to confirm disk or memory replacement, compare Size, Model and Serial Number with the previous period. If low free space is being investigated, focus on Logical Disks, Free Space and Free Space Percent.


Data quality in monitoring hardware snapshots

The data quality section helps assess whether hardware audit records have complete details and whether daily summaries match the item list. In this view, that matters a lot because missing details may make you see the item count in the panel without being able to point to the exact model, manufacturer or category.

Messages may refer to missing hardware details, invalid JSON structure, items outside daily record boundaries, details not matching the summary, the current day still being aggregated, historical records left open after time or elapsed days without hardware audit data.

Hourly Presence in this view only says during which local hour the hardware audit snapshot was collected. It does not show the number of hardware items in that hour and does not mean user work. Hourly filtering is unavailable because the active-hours mask stores snapshot presence and does not assign hardware counters to individual hours.


Settings for monitoring automatic hardware audit

Data for the Audit - hardware view depends on monitoring profile settings in the Audit area. The editable switch linked with this page is Hardware Audit in the Automatic Audit section. When enabled, the agent can collect daily hardware snapshots used by this manual page.

The settings panel also shows Hardware and Software Audit Interval (minutes), Maximum Hardware Audit Items per Class, Include Raw Audit Properties and Hardware WMI Audit Classes. These options affect data scope, but in the current configuration they are read-only, so the user does not change them directly from this panel.

After enabling Hardware Audit, wait for the next daily snapshot. Then return to Audit - hardware and check Hardware Items, Hardware Categories, Total Physical Memory, Total Disk Size, Logical Disk Free Percent and anomalies related to hardware changes and missing categories.