How to open printer audit monitoring?
Use the application menu path: Menu -> Monitoring -> Audit - printers. This page describes a daily snapshot of printer configuration saved on computers, not a list of completed print jobs. The agent collects an automatic inventory: Printer Count, Default Printer Count, Local Printer Count, Network Printer Count, Shared Printer Count, Print To File Printer Count, PDF Printer Count, Virtual Printer Count, as well as Printer Driver Count, Printer Port Count, statuses, and locations.
Open this view when you want to check whether workstations have the correct default printer, whether new network printers appeared, whether drivers or ports disappeared, and whether print configuration differs from the previous audit. Printer audit monitoring helps when cleaning up the print environment, checking printer mappings, reviewing changes after system updates, and inspecting workstations after user reports.
This view is built from the analytics panel, daily printer snapshots, and a drill-down area for the selected record. The panel is explained below because it shows the current picture built from the latest snapshot of each computer in the selected date range. One table row corresponds to a daily audit of one machine. After clicking a record, the application opens the list of printers assigned to that specific snapshot, showing printer name, type, driver, port, status, share, location, and default printer flag for the selected computer and employee.
Daily table in printer configuration monitoring
The table presents the state of printers detected on a computer on a given day. Read it as a configuration audit result, not as a printer usage report. If a printer was visible when the snapshot was collected, the record stores its type, driver, port, status, and information about location and sharing.
The most important columns help you assess the workstation quickly:
- Printers - the total number of printers visible in the snapshot.
- Default Printer Count - information about whether the computer has a default printer set.
- Network Printer Count - printers assigned through the network or mappings.
- PDF Printer Count and Virtual Printer Count - devices that often do not represent physical hardware.
- Printer Driver Count - the number of different drivers recognized in details.
- Printer Port Count - the number of ports used by detected printers.
The record may also include Local Printer Count, Shared Printer Count, Print To File Printer Count, Printer Status Count, Printers With Location, and percentage shares of individual groups. The search field can find data by date, agent, computer, Windows user, active hours, default printer, last printer name, driver, port, status, share name, location, and raw JSON data.
Analytics panel in printer snapshot monitoring
The analytics panel does not repeatedly sum the same printers across many days. For the current environment picture it uses the latest available record for each computer, so metrics such as Printers, Default Printer Count, PDF Printer Count, Virtual Printer Count, Printer Driver Count, and Printer Port Count show the fleet state in the selected range.
The most useful panel metrics are:
- Printers - the scale of print configuration on monitored computers.
- Default Printer Count - a quick signal showing whether computers have a primary printer selected.
- PDF Printer Count - the number of file printers or similar PDF solutions.
- Virtual Printer Count - printers that do not point directly to physical hardware.
- Printer Driver Count - driver diversity in the environment.
- Printer Port Count - the range of ports and mappings used by printers.
A practical way to read the panel is to compare printer count with driver and port counts. A small number of printers with many drivers may indicate leftovers from earlier configurations, while a high number of network printers may point to extensive print resource mapping.
Rankings in monitoring printer names, drivers, and ports
Rankings show which printers, drivers, ports, statuses, and printer types appear most often in the latest snapshots. The default Printers tab helps you quickly notice popular models, system printer names, or entries repeated on many computers.
The rankings panel includes:
- Printers - the most frequently visible printer names.
- Printer Drivers - drivers used by detected printers.
- Printer Types - a split into local, network, shared, PDF, virtual, and print-to-file printers.
- Printer Ports - ports and mappings found in details.
- Printer Statuses - status values reported for printers in snapshots.
- Computers and Employees - workstations and people ranked by printer count.
If an old or unusual entry appears in the driver ranking, it is worth opening details and checking which computers use it. For ports, comparing port names with network printers helps identify obsolete mappings.
Trends in monitoring printer configuration changes
Trends show how daily printer snapshots changed over time. They do not describe printed pages or documents, only configuration state: how many printers were visible, how many were default, local, network, shared, PDF, virtual, how many had a location, and how driver, port, and status counts changed.
Available charts include Printer Count, Default Printer Count, Local Printer Count, Network Printer Count, Shared Printer Count, Print To File Printer Count, PDF Printer Count, Virtual Printer Count, Printer Driver Count, Printer Port Count, Printer Status Count, Printers With Location, and percentage shares of selected types.
In practice, jumps are the most valuable signal. A sudden increase in network printers may mean a change in mappings or policies, a decrease in default printers may affect users, and a change in printer driver count often requires checking whether an update or installation left unwanted entries.
Comparisons in printer audit monitoring
The comparisons tab places the current range next to a reference period and lets you check whether printer configuration changed noticeably. This is useful after print server migration, new printer rollout, mapping policy changes, driver updates, or cleanup of PDF and virtual printers.
Most often it is worth comparing:
- Printers - whether the overall printer count increased or decreased.
- Default Printer Count - whether computers still have a primary printer set.
- PDF Printer Count and Virtual Printer Count - whether non-physical devices changed.
- Printer Driver Count - whether the environment grew by new drivers.
- Printer Port Count - whether new ports or mappings appeared.
- Computers and Employees - whether the change affects a group or individual workstations.
If the difference is large, start with computers that have the highest printer count and open details. There you can see more easily whether the change concerns one default printer, a group of network printers, a new port, or another driver.
Anomalies in monitoring printer and driver changes
Anomalies in the Audit - printers view point to situations that may require checking computer configuration. The mechanism compares the latest snapshot with the baseline period and looks for printer count changes, missing default printer, changed default printer, network printer changes, and driver count changes.
The panel may report, among other things:
- Printer count changed significantly - the computer has a noticeably different number of printers than in the reference period.
- Default printer is missing - printers are installed on the computer, but no default printer was detected.
- Default printer changed - the default printer name differs from the previous period.
- Network printer count changed significantly - the number of printers coming from the network or mappings changed.
- Printer driver count changed - the number of detected drivers differs from the baseline value.
In anomaly evidence, check Current Printer Count and Baseline Printer Count, Current Default Printer and Baseline Default Printer, Current Network Printer Count and Baseline Network Printer Count, Current Printer Driver Count and Baseline Printer Driver Count, and Most Common Printer Driver. For network printer changes, also check mappings and print server availability.
Record details in printer audit monitoring
After opening a record, you see the list of printers from one daily computer snapshot. Details are sorted so that the default printer is visible first, followed by entries ordered by printer type and printer name.
The details include, among other things:
- Printer Name, Printer Type, Driver Name, and Port Name.
- Status, Share Name, and Location, if they were saved in the system.
- Flags: Is Default, Is Local, Is Network, Is Shared, and Is Print To File.
- Information: Is PDF Printer, Is Virtual Printer, and Has Location.
- First seen, last seen, Active Hours, Observation Count, and Inventory Share.
- Raw status, useful when a technical value needs to be compared with the label visible in the application.
When analyzing a problem, start with the default printer, driver, and port. If the user reports a missing network printer, compare Printer Type with Port Name and Share Name. If the issue concerns PDF, check the Is PDF Printer flag and the driver.
Data quality in printer snapshot monitoring
The data quality section tells you whether printer audit records have details that match the summary. This matters because Printer Count alone is not enough if you cannot open the printer name, driver, port, or information about which printer is default.
Messages may indicate missing printer details, invalid JSON structure, details outside daily record boundaries, a mismatch between details and summary, the current day still being aggregated, historical records left open, or elapsed days without printer audit data.
Hourly presence shows only the local hour when the printer audit snapshot was saved. It does not mean the number of printers in that hour and is not a user activity chart. Hourly filtering is not available because ActiveHoursMask stores snapshot presence and does not assign printer counters to individual hours.
Settings for printer audit monitoring
Data for the Audit - printers view is linked with monitoring profiles in the Printing area. In the settings panel there is a Printer Inventory section with the Printer Inventory option, which is responsible for printer inventory, but in the current configuration it is read-only.
This means the user can see here whether printer audit is part of the profile, but should not treat this option as a regular editable switch in the form. Editable settings related to print job monitoring, such as print monitoring or PDF fallback, describe a different data scope and do not replace the daily printer inventory.
When the agent profile configuration is changed centrally, give the agent time to save a new daily snapshot. Then reopen Audit - printers and check Printers, default printer, network printers, drivers, ports, statuses, and anomalies related to configuration changes.
