How to open software audit monitoring?

Use this navigation path in Codenica: Menu -> Monitoring -> Audit - software. This is not an application usage screen and not a real-time installation log. The page describes a daily software inventory snapshot collected by the agent from the registry and system sources. The record includes Software Count, Visible Software Count, System Component Count, Publisher Count, Estimated Software Size, average software per computer, and information about computers and employees included in the audit.

Use this view when you want to check which applications are installed on computers, whether new entries appeared, whether previously known programs disappeared, how many entries have no publisher or version, and whether software exposes an uninstall command. Software audit monitoring helps with license checks, environment cleanup, post-deployment analysis, and detection of packages that may have been installed outside the standard process.

The view consists of an Analytics Panel, a table of daily snapshots, and details for the selected record. The panel is described below because it aggregates the latest computer snapshots from the chosen date range. Each row represents one daily software state stored for a specific machine. After opening the record, the application shows the items from that snapshot: software name, version, publisher, installation scope, visibility, size, install date and location, registry entry, and uninstall command data.


Daily table in installed software monitoring

The table shows the software state detected on a computer for the selected day. Read it as an audit of the installation list, not as a history of program launches. If an entry was visible when the snapshot was collected, the record keeps its name, publisher, version, registry entry, installation scope, and additional quality counters.

Start with:

  • Software Count - the full number of collected items after entry grouping.
  • Visible Software Count - applications that usually matter most for user-facing checks.
  • System Component Count - technical entries that should not always be treated as ordinary applications.
  • Estimated Software Size - an approximate sum of sizes reported by installation entries.
  • Publisher Count - a quick indication of how broad the application source base is on a computer.
  • Entries without a publisher, without a version, with an uninstall command, or with a quiet uninstall command.

Additional columns may include Registry Entry Count, Hidden Entry Count, User Software Count, Machine Software Count, the most common Registry Hive and Registry View, plus the last detected software, version, publisher, install date, install location, and Uninstall Command Source. Search helps you find a record by date, computer, employee, agent, software name, publisher, version, registry data, or details JSON content.


Analytics panel in application inventory monitoring

The analytics panel does not add the same programs across many days. It takes the latest snapshot of every computer in the selected period and uses it to present the current software estate. Because of that, Software Count, Visible Software Count, System Component Count, Publisher Count, and Estimated Software Size describe the current computer fleet rather than repeated daily copies.

The most useful panel metrics are:

  • Software Count - the size of the entire detected entry library.
  • Visible Software Count - programs that most often need business or licensing review.
  • System Component Count - technical components installed with the system, drivers, or supporting packages.
  • Publisher Count - a fast signal that the environment may be highly fragmented.
  • Estimated Software Size - an indicative weight of installations reported by the system.
  • Average software per computer - useful for comparing machines with each other.

Read these values together. A high program count is not automatically a problem, but a sudden size increase, more publishers, or fewer versioned items can point to a change in how applications are installed or detected.


Rankings in publisher and software version monitoring

Rankings show which inventory elements dominate the latest snapshots. The panel opens Software by default, so the most frequently detected program names are visible immediately. This is a practical starting point when checking whether common packages match the company standard.

The available views include:

  • Software - the most common application and entry names.
  • Software Publishers - companies or vendors present in installation data.
  • Software Versions - detected version distribution, useful for update checks.
  • Software Scopes - split between user, machine, and unknown installations.
  • Software Visibility - visible entries, hidden entries, and system components.
  • Computers and Employees - aggregations showing where the highest number of entries appears.

If a publisher or version ranking contains an unusual item, open the record details and check the installation path and registry key. For license auditing, combining software name with publisher and version is more reliable than the name alone, because names can be too generic.


Trends in software inventory monitoring

Trends show how daily software snapshots changed over time. They are a series of states collected by the agent, not a list of individual install or removal operations. This lets you see whether the application estate is growing, whether the visible program count is falling, whether system components are increasing, and whether reported software size moves as expected.

The charts cover Software Count, Visible Software Count, System Component Count, Publisher Count, Estimated Software Size, Average software per computer, Computers, and Employees.

Sudden jumps and drops carry the most value. Growth in entries can mean package rollout, components added by an update, or a change in scan sources. A decline may come from uninstall activity, system cleanup, or an incomplete snapshot. If size changes more strongly than the program count, inspect the largest estimated-size applications in the details.


Comparisons in application audit monitoring

The Comparisons tab places the current date range next to a reference period. In a software audit, this is especially useful after deployments, system image updates, user migrations, or workstation cleanup. The comparison helps decide whether the change affects the whole fleet or only selected machines.

It is worth comparing:

  • Software Count - whether the overall inventory size increased or decreased.
  • Visible Software Count - whether the number of user-relevant applications changed.
  • System Component Count - whether updates added many technical entries.
  • Publisher Count - whether new software sources appeared.
  • Estimated Software Size - whether a computer gained a large package or toolset.
  • Computers and Employees - whether the difference comes from new data or an actual configuration change.

If the comparison shows a clear difference, start with computers that changed the most and open their details. Then check new or missing program names, publishers, versions, and registry entry sources.


Anomalies in daily software audit monitoring

Anomalies in Audit - software detect situations that may require administrative, licensing, or security review. The mechanism compares current snapshots with the baseline period and analyzes both entry counts and specific items on the list.

The panel can report:

  • Software count changed significantly - the current number of detected entries differs clearly from the comparison period.
  • Estimated software size changed significantly - the sum of reported sizes increased or decreased beyond the rule threshold.
  • New software detected - an item is present in the current audit but was absent in the reference period.
  • Software no longer detected - an entry existed earlier but disappeared from the current snapshot.
  • Many software entries do not have an uninstall command - the rule may indicate packages that are harder to manage automatically.

In anomaly evidence, check Current software count, Baseline software count, current and baseline estimated size, minimum change threshold, program name, publisher, version, scope, visibility, registry entry, and uninstall command information. A new item is not always risky, but it should match the installation policy and the purpose of the computer.


Record details in software list monitoring

After entering a record, you see items collected in the daily state of a specific computer. The list places visible software first, then system components and remaining entries, and sorts data by program name within those groups. This makes it easier to separate user applications from technical registry entries.

Details include, among others:

  • Software Name - the name visible in installation data.
  • Display Version and Publisher - the basis for checking freshness and package origin.
  • Scope - user, machine, or unknown installation.
  • Visibility - visible item, hidden item, or system component.
  • Estimated Size, Install Date, Install Location, First Seen, Last Seen, and Active Hours.
  • Registry Hive, Registry View, Registry Key, Uninstall Command Source, and whether quiet uninstall is available.

During analysis, start with the name, publisher, and version, and only then move to the registry entry. For packages without a publisher or version, the installation location is worth checking because it helps distinguish a full application from a residual or technical entry.


Data quality in software snapshot monitoring

The data quality section checks whether the daily software audit summary is consistent with the details list. This matters because Software Count without names, publishers, and versions is not enough for reliable inventory work.

Messages may refer to missing details despite existing counters, invalid JSON structure, entries outside daily record boundaries, mismatches between summary and details, the current day still being aggregated, a historical record left open, or elapsed days without software audit data.

Hourly presence shows only the local hour in which the agent stored the audit snapshot. It does not show the number of entries or program activity during that hour. Hourly filtering is not available because ActiveHoursMask stores snapshot presence, while software counters are not assigned to individual hours.


Settings for software audit monitoring

Data for this view is connected with monitoring profiles in Automatic Audit and the Software Audit subsection. The editable control is Software Audit, which decides whether the agent collects the daily software inventory.

The same area shows Hardware and Software Audit Interval (minutes), but in the current configuration it is read-only. The Software Audit subsection also displays Maximum Software Audit Items and Software Registry Audit Sources. The sources include HKLM 64-bit Uninstall, HKLM 32-bit Uninstall, and HKCU Uninstall, although these settings are currently informational.

After enabling the profile or adjusting central settings, give the agent time to store the next daily state. Then reopen Audit - software and review Software Count, Visible Software Count, system components, publishers, versions, size, and anomalies for new or disappearing items.