How to open peripheral audit monitoring?
Open the view from the application menu: Menu -> Monitoring -> Audit - devices. This page describes a daily snapshot of peripheral devices visible in Windows, not a continuous log of every connection and disconnection. The agent stores an automatic inventory of peripherals: Peripheral Device Count, USB Peripheral Device Count, Bluetooth devices, media devices, HID devices, monitors, keyboards, mice, statuses, device classes, and manufacturers.
Use this view when you want to check which devices are visible on computers, whether the USB peripheral count changed compared with the previous audit, whether devices with Warning or Error status appeared, and whether some devices have no recognized class. Peripheral audit monitoring is useful during workstation checks, after accessory replacement, after device-related support tickets, and when reviewing unexpected peripherals in the environment.
The view consists of the analytics panel, the list of daily snapshots, and record details. The panel is described below because it uses the latest snapshot saved for each computer in the selected date range. Each table row represents one daily audit of one machine. After opening a record, the application shows devices from that snapshot for the selected computer and employee, together with name, type, class, manufacturer, status, and USB, Bluetooth, printer, camera, HID, and connection flags.
Daily table in peripheral computer monitoring
The table shows the daily state of peripheral devices on computers. Read it as an audit state, not as a history of every plug-in or removal operation. If a device was visible when the snapshot was collected, it is included in the record with its classification and status.
In the main columns, pay attention to:
- Peripheral Device Count - the total number of devices registered in the snapshot.
- USB Peripheral Device Count - peripherals recognized as USB-related.
- Bluetooth Peripheral Device Count - devices detected as Bluetooth.
- HID peripheral devices - keyboards, mice, and other HID interface devices.
- Peripheral Problem Device Count - the combined number of warnings and errors.
- Unknown peripheral classes - devices whose class was not correctly recognized.
The record also contains printer, camera, media, monitor, connected and disconnected device counts, status counts, and the most common class, manufacturer, and status. The search field covers date, agent, computer, Windows user, active hours, device classes, manufacturers, statuses, last device name, device ID, and technical JSON details.
Analytics panel in peripheral snapshot monitoring
The analytics panel summarizes the selected range, but it builds the current environment picture from the latest record of each computer. This way Peripheral Device Count, USB Peripheral Device Count, Peripheral Device Class Count, and Peripheral Manufacturer Count show the current fleet state instead of summing the same devices across many days.
The most important panel metrics are:
- Peripheral Device Count - the full volume of peripherals in the latest snapshots.
- USB Peripheral Device Count - the scope of USB-related devices.
- Bluetooth Peripheral Device Count and Media Peripheral Device Count - a split by communication type and function.
- HID peripheral devices - the group covering input hardware and human interface devices.
- Peripheral Problem Device Count - device warnings and errors.
- Computers and Employees - the scope of records included in the analysis.
During the first review, compare the number of devices with the number of classes and manufacturers. A high device count with a low class count can mean a repeatable workstation setup, but it may also point to limited classification quality.
Rankings in monitoring device classes and types
Rankings help you quickly see which peripherals, classes, and manufacturers dominate the environment. The default tab shows Peripheral Device Names, so you can immediately spot the most common models or generic names reported by Windows.
The panel includes:
- Peripheral Device Names - devices most often visible in snapshots.
- Peripheral Device Types - groups such as USB device, Bluetooth device, media device, camera, or HID interface device.
- Peripheral Device Classes - classes reported by the system and used to organize the inventory.
- Peripheral Manufacturers - a summary of manufacturers detected in details.
- Peripheral Statuses and Peripheral Status Groups - the distribution between connected, disconnected, warning, error, and unknown statuses.
- Computers and Employees - rankings by device count in the latest snapshots.
Rankings are a good starting point when looking for exceptions. An unusual manufacturer, a large number of USB devices on one computer, or a growing share of problem statuses should usually lead you to the record details.
Trends in monitoring peripheral changes over time
Trends show how daily peripheral device states changed. They are not an exact connection timeline, but a series of snapshots where you can see increases or decreases in devices, USB, Bluetooth, HID, problem devices, and unrecognized classes.
Available charts cover Peripheral Device Count, USB Peripheral Device Count, Bluetooth, media, monitor, HID, printer, camera, keyboard, mouse, connected and disconnected devices, devices with warning, error or unknown status, and percentage shares of selected groups.
When analyzing trends, watch for sudden jumps. An increase in USB devices may mean new accessories, docking stations, or other devices reported by Windows. An increase in Peripheral Problem Device Count should be checked in details, because it usually indicates a driver, device, or classification issue.
Comparisons in monitoring peripheral device changes
Comparisons place the current range next to a baseline period and help assess whether the peripheral state on computers changed noticeably. In device audit, this is useful after replacing accessories, changing docking stations, service work, or cleaning up workstation equipment.
It is worth checking mainly:
- Peripheral Device Count - shows the overall change in detected device volume.
- USB Peripheral Device Count - helps assess changes in accessories and wired devices.
- Bluetooth Peripheral Device Count and media devices - show shifts between device types.
- HID peripheral devices - useful when checking keyboards, mice, and similar input devices.
- Peripheral Problem Device Count - lets you see whether warnings or errors increased.
- Peripheral Device Class Count and Peripheral Manufacturer Count - show hardware diversity.
If the comparison shows a large increase, first check whether it affects the whole group of computers or a single device. For one workstation, open the details and review Device Name, Device Type, Device Class, Manufacturer, and Device Status.
Anomalies in monitoring peripheral device problems
Anomalies in the Audit - devices view point to changes or states that may require administrator action. The mechanism compares the latest snapshot with a reference period and also checks whether records contain warnings, errors, or missing device classes.
The panel may show these situations:
- Peripheral device count changed significantly - the number of detected peripherals on a computer differs from the baseline period.
- USB peripheral device count changed significantly - the number of USB devices visible in the daily snapshot changed.
- Peripheral device reports a problem - one or more devices has Warning or Error status.
- Peripheral devices without a class were detected - the system did not provide a recognized device class.
In anomaly evidence, check Current Peripheral Device Count, Baseline Peripheral Device Count, Current and Baseline USB Device Count, warning count, error count, Device Name, Device Class, Device Status, and Manufacturer. For device errors, it is also worth verifying them in Windows Device Manager.
Record details in peripheral audit monitoring
After clicking a record, you see the list of devices from one daily computer snapshot. Details are sorted by Device Type, Device Class, and Device Name, which makes it easier to move from a general group to a specific peripheral.
The details include, among other things:
- Device Name and Device ID, useful for identifying the exact system entry.
- Device Type and Device Class, which organize peripherals by function and by the class reported by Windows.
- Manufacturer, Device Status, and Status Group, which are the basis for checking whether the device works correctly.
- Flags: Is USB, Is Bluetooth, Is Printer, Is Camera, Is Media Device, Is Monitor, Is Keyboard, Is Mouse, and Is HID Device.
- Information: Is Connected, Is Disconnected, Has Warning, Has Error, and Has Unknown Status.
- First detection, last detection, Active Hours, Observation Count, and inventory share.
If you analyze a problematic device, start with Device Status and Status Group. If you investigate an unexpected USB device, filter by the Is USB flag, then check the name, manufacturer, and device identifier.
Data quality in peripheral snapshot monitoring
The data quality section tells you whether daily peripheral audit records have details that match the summary. This matters because the device counter alone is not enough if you cannot open the name, class, status, or manufacturer of a specific peripheral.
Messages may indicate a missing device list, invalid JSON, items that do not fit the audit range, a mismatch between counters and details, a record from a day that may still be completed, an older snapshot without a proper close, or a finished day without peripheral data.
Hourly presence shows only the local hour when the peripheral audit snapshot was collected. It does not show the number of devices in a given hour and does not describe user activity. Hourly filtering is not available because the mask stores snapshot presence, not device counters assigned to individual hours.
Settings for peripheral device audit monitoring
Data for the Audit - devices view is linked with monitoring profiles in the Audit area, under Connected Device Audit. The panel shows the Peripheral Device Audit option, but in the current settings configuration it is read-only, so the user does not change it directly from this place.
This distinction matters when testing the manual page: we describe the setting and its impact on data, but we do not treat it as a regular editable switch. If this area is centrally managed in your installation, changes to peripheral snapshot collection should be made where the agent profile is maintained.
After changing the device audit configuration, wait for the next daily snapshot. Then return to Audit - devices and check Peripheral Device Count, USB device count, statuses, device classes, and anomalies related to problems and missing recognized classes.
