How to open services audit monitoring?

Use this path in the application: Menu -> Monitoring -> Audit - services. This page describes a daily snapshot of Windows services saved on computers, not a live process view or a system event log. The agent performs an automatic inventory: Service count, Running service count, Automatic service count, Disabled service count, Important service count, Important service warning count, and statuses for Defender, Windows Update, Spooler, WinRM, and Remote Registry.

Use this view when you want to check whether important services are running, whether Microsoft Defender has stopped, whether Remote Registry is enabled where it should not be, or whether the number of services changed after software installation. Services audit monitoring helps with system state checks, review of changes after updates, analysis of unexpected services, and comparison of computer configurations.

The view consists of the analytics panel, the table of daily snapshots, and record details. The panel is discussed below because it relies on the newest snapshot saved for each computer in the selected date range. A single table row means one daily services audit of one machine. After entering the record, the application presents services saved in that specific computer state: display name, system name, status, start type, service type, source, and important-service flag for the related computer and employee.


Daily table in Windows services monitoring

The table shows the state of services detected on a computer on a specific day. Treat it as a service configuration audit result, not as minute-by-minute system monitoring. If a service was present while the snapshot was collected, the record stores its status, start type, service type, and whether it belongs to the important-services group.

First, pay attention to:

  • Service count - the full size of the service inventory on the computer.
  • Running service count and stopped services - a quick picture of current service state.
  • Important service warning count - a signal that one important service is not running.
  • Defender and Windows Update - service statuses important for security and updates.
  • Spooler, WinRM, and Remote Registry - services often relevant for administration, printing, or remote access.
  • Automatic, Manual, and Disabled - the distribution of service start types.

The record may also include counts for own-process services, shared-process services, interactive services, most common status, most common start type, last service, and last service name. Search covers date, agent, computer, Windows user, active hours, key service statuses, last service, status, start type, and JSON details content.


Analytics panel in service snapshot monitoring

The analytics panel builds the current picture from the last record of each computer. As a result, Service count, Running service count, Important service count, Important service warning count, Automatic service count, and Disabled service count describe the current environment state instead of summing the same services from consecutive days.

The most important panel metrics are:

  • Service count - the full number of services found in the latest snapshots.
  • Running service count - how many services have the Running status.
  • Important service count - services marked as especially relevant for system operation or security.
  • Important service warning count - important services that are not running.
  • Automatic service count - services configured to start automatically.
  • Disabled service count - services set to Disabled.

When reading the panel, compare service count with the number of warnings. A high service count alone does not need to indicate a problem, but an increase in important service warnings or a stopped Defender service should lead you to record details.


Rankings in monitoring service statuses and start types

Rankings and distributions help show where unusual service states are concentrated. The default Important Service Warnings tab shows computers where important services without Running status were detected, so it is a useful starting point for risk checks.

The panel includes:

  • Important Service Warnings - a ranking of computers with problems in services marked as important.
  • Service Statuses - the distribution of running and stopped services.
  • Service Start Types - a split into Automatic, Manual, and Disabled.
  • Computers - machines ranked by service count, with additional warning information.
  • Employees - aggregation by employees linked with records.

If a computer appears in the important warnings ranking, open its record and check service names. Start-type distribution is worth reading together with trends, because a sudden shift of many services to Disabled may mean a policy change, installer action, or system configuration change.


Trends in monitoring system service changes

Trends show how daily service snapshots changed over time. The charts are not a list of service starts and stops, but a series of states collected by the agent. This makes it possible to see whether service count is growing, whether automatic services are changing, whether important service warnings appear, and whether the audited computer scope remains stable.

Available charts include Service count, Running service count, Automatic service count, Disabled service count, Important service count, Important service warning count, Computers, and Employees.

Sudden changes matter most. An increase in service count may result from software installation or a system update, a decrease may indicate uninstall activity or a collection issue, and a jump in important service warnings usually requires quick checking of specific service names in details.


Comparisons in services audit monitoring

The Comparisons tab contrasts the analyzed period with the baseline and helps assess whether service state on computers changed noticeably. This is useful after software deployment, security policy changes, system updates, or administrative work that may have added, removed, or switched services.

Most often it is worth comparing:

  • Service count - whether computers gained or lost services.
  • Running service count - whether the operating state of services changed.
  • Automatic service count - whether more services now start with the system.
  • Disabled service count - whether configuration was hardened or changed accidentally.
  • Important service count and Important service warning count - whether critical services still work correctly.
  • Computers and Employees - whether the change affects the whole scope or individual machines.

If the comparison shows a large difference, start with computers that have the highest important service warning count. Then go to details and check whether the change concerns Defender, Windows Update, Remote Registry, the application’s own service, or another component.


Anomalies in critical service monitoring

Anomalies in the Audit - services view focus on situations that may have operational or security significance. The mechanism checks the newest snapshots, compares service count with the baseline period, and separately controls selected Windows services.

The panel may report these cases:

  • Important service is not running - at least one service marked as important does not have Running status.
  • Microsoft Defender service is not running - the WinDefend service exists but is not running in the latest snapshot.
  • Remote Registry service is running - the RemoteRegistry service is running, which in many environments should be a deliberate administrative decision.
  • Service count changed significantly - the number of detected services differs from the comparison period.

In anomaly evidence, check Important service warning count, Important service count, WinDefend status, RemoteRegistry status, Current service count, Baseline service count, and the minimum change threshold. For security services, it is also worth comparing the result with company policy, because not every status change is accidental.


Record details in services audit monitoring

After clicking a record, you see the set of services saved in the computer’s daily state. The list places important services first and orders the remaining entries by display name, making it easy to move from an alert to a concrete service.

The details include, among other things:

  • Service, meaning the display name shown to the user or administrator.
  • Service name - the technical system name, useful in PowerShell, Windows Services, and policies.
  • Status - for example Running or Stopped.
  • Start type - Automatic, Manual, or Disabled.
  • Important - a flag indicating a service watched more carefully.
  • Service type, Source, First Seen, Last Seen, and Active Hours.

During diagnosis, start with important services and the statuses of Defender, Windows Update, and Remote Registry. If a service is stopped, check its start type: a manual service should be interpreted differently than an automatic service that should run after system startup.


Data quality in service snapshot monitoring

The data quality section checks whether the services audit summary can be connected with the details list. This matters because Service count without names, statuses, and start types is not enough for a reliable diagnosis of system configuration.

Messages may refer to missing service details despite an existing summary, invalid JSON, entries outside daily record boundaries, mismatch between counters and details, the current day still being processed, a closed record without a service list, or elapsed days without services audit data.

Hourly presence means only the local hour in which the services audit snapshot was saved. It is not a measurement of user activity and does not show how many services were running in that time window. Hourly filtering is not available because daily service snapshots represent a captured inventory state, not counters assigned to hours.


Settings for services audit monitoring

Data for the Audit - services view is linked with monitoring profiles in the Endpoint State Audit area. This section shows the Services Audit option, responsible for the system services snapshot, but in the current profile configuration it is read-only.

In practice, you can confirm here that services audit is present in the profile, but you cannot change this option directly from the form. The same area also contains Process Audit, Users and Sessions Audit, and Endpoint State Audit Interval (minutes), but for this view the key data comes from Services Audit.

After a central change of the agent profile, wait for a new services snapshot to be saved. Then return to Audit - services and check Service count, important service statuses, Defender, Windows Update, Remote Registry, and anomalies related to service count changes or stopped critical services.