How to open audit summary monitoring?

Use this path in the application: Menu -> Monitoring -> Audit - summary. This page does not describe one asset type; it describes a combined daily snapshot of automatic inventory. In one record, the application brings together Audited Items, Audit Areas, Hardware, Software, USB, Printers, Peripherals, Security, Accounts, Services, and the number of computers and employees covered by the data.

Open this view when you want to check whether the audit collected all expected parts of the environment. Audit summary monitoring is useful before moving to detailed hardware, software, service, or account pages, because it immediately shows which audit area contains the most items, where the inventory scale changed, and whether an entire snapshot category is missing.

The view contains an Analytics Panel, a table of daily summaries, and details for the selected record. The panel is described in the following sections because it uses the latest computer states from the selected period. A single table entry refers to one day and one machine, and after opening it you see a list of audit snapshots with audit area, snapshot type, Items Found, capture time, update time, and source data.


Summary table in daily audit monitoring

The table acts as an index for the whole inventory from a given day. Instead of listing concrete disks, applications, or accounts, it presents counts gathered from individual audit areas. This makes it easy to see whether a computer has complete audit data and whether proportions between categories look reasonable.

The most important columns are:

  • Total Items - the sum of all items detected in the daily summary.
  • Hardware - the number of items from the hardware audit.
  • Software - entries from the software inventory.
  • Printers - items collected by the printer audit.
  • Services, Accounts, Peripherals, Security, and USB - additional areas used to assess completeness.
  • Audit Status, Snapshots, Audit Types, Most common snapshot type, Last snapshot type, and Last snapshot key.

If a row has a low number of audit areas or an unusually small number of snapshots, treat it as a signal to check the agent profile or data quality. Search can locate a record by date, computer, employee, agent, status, snapshot type, or details JSON content.


Analytics panel in audit completeness monitoring

The analytics panel builds the current picture from the latest summary of every computer in the selected range. It does not repeatedly add the same items from consecutive days; it shows the last known audit state for machines covered by the filter. Because of that, Audited Items and Audit Areas are a good starting point for checking whether automatic inventory runs evenly.

In the panel, watch especially:

  • Audited Items - the total number of positions detected in the latest snapshots.
  • Audit Areas - how many inventory categories were actually collected.
  • Hardware, Software, Services, and Accounts - areas that are usually the most important for evaluating computer state.
  • Printers, Peripherals, Security, and USB - categories helpful for equipment and risk analysis.
  • Computers and Employees - the data scope that determines whether the result describes one machine or a larger group.

If audited items decrease while the computer count stays similar, check whether one audit area disappeared. If only one category grows, move to the detailed view for that category and decide whether the change is expected.


Rankings in automatic inventory area monitoring

Rankings in this view answer where most audit data comes from. The default Audit Areas tab shows the share of hardware, software, printers, services, accounts, security, USB, and peripherals within the whole inventory.

The main views are:

  • Audit Areas - categories ranked by the number of found items.
  • Audit Types - distribution of concrete snapshot types registered by the agent.
  • Audit Statuses - information about whether collection ended in the expected state.
  • Computers - machines with the highest number of audited items and additional snapshot type information.
  • Employees - aggregation by people linked with records.

Rankings help detect missing or overly dominant areas. If Software suddenly outweighs the other categories, it may mean a larger number of installation entries. If Hardware or Services disappears, check profile settings first and then open record details.


Trends in audited item cross-section monitoring

Trends show how the combined audit picture changed over consecutive days. The charts are based on daily states, so they are best for observing direction across the whole automatic inventory, not for tracking a single event.

The available series include Audited Items, Hardware, Software, Services, Accounts, Peripherals, Printers, Security, USB, Audit Areas, Computers, and Employees.

The most useful signals are differences between areas. A stable computer count combined with fewer Audited Items can suggest incomplete data collection. A sudden increase only in software, printers, or accounts should lead you to the matching detailed view, where concrete items are visible.


Comparisons in combined computer audit monitoring

In the Comparisons tab, current data is shown next to the baseline period, making it easier to judge whether the whole inventory moved in a meaningful way. This view is especially helpful after monitoring profile changes, agent rollout to new computers, system updates, or environment cleanup.

It is usually worth comparing:

  • Audited Items - whether the total inventory scale increased or decreased.
  • Audit Areas - whether the number of collected categories remains stable.
  • Hardware and Software - whether core snapshots still have a similar volume.
  • Services and Accounts - whether endpoint state data did not disappear after profile changes.
  • Printers, USB, Security, and Peripherals - whether additional areas were omitted.
  • Computers and Employees - whether the change comes from data scope rather than the audit itself.

If comparison shows a large drop, start with the area that changed the most and inspect record details. For a strong increase, check whether new snapshot types, new computers, or a wider scanning scope were added.


Anomalies in missing and changed audit monitoring

Anomalies in Audit - summary focus on completeness and scale of automatic inventory. The mechanism compares the current snapshot with the baseline period and checks whether item counts changed, whether categories are missing, and whether collection status differs from the expected state.

The panel can report:

  • Audit item count changed significantly - the total number of items differs from the comparison period.
  • Audit area item count changed significantly - the change affects a concrete category, such as hardware or software.
  • Audit area is missing - an expected category is absent from the latest snapshot.
  • Audit snapshot type is missing - a specific snapshot that should have been collected is not present.
  • Audit collection status changed - the current status differs from the previous or expected state.

In anomaly evidence, check Current Audit Item Count, Baseline Audit Item Count, Current Item Count, Baseline Item Count, Missing Audit Area, Audit Area Count, Audit Type Count, Current Audit Status, Baseline Audit Status, and Expected Audit Status. First decide whether the issue is data-related, profile-related, or caused by a real change on the computer.


Record details in audit snapshot monitoring

After opening a record, you see the list of snapshots that form the daily summary. The list is sorted by Items Found, so the largest parts of the audit appear first. This helps assess whether hardware, software, services, accounts, printers, USB, security, or peripherals dominate.

Details include, among others:

  • Audit Area - the main category, for example Hardware, Software, or Services.
  • Audit Snapshot - the name of the concrete snapshot that supplied data.
  • Items Found - the number of entries in this part of the summary.
  • Captured At, Updated At, First Seen, Last Seen, and Active Hours.
  • Share Percent, Snapshot Type, Snapshot Key, Source, and Category.

If any area has zero or noticeably fewer items than usual, move to the appropriate detailed audit page. The summary shows where the issue is located, while specific device, program, account, or service names are available in specialized views.


Data quality in inventory summary monitoring

The data quality section checks whether numbers stored in the daily summary agree with the snapshot list in details. This matters because without consistency between summary and details, it is hard to tell whether a missing category is a real collection problem or only a data preparation issue.

Messages can indicate a missing detail list despite existing snapshots, invalid JSON, entries outside the record day, counter mismatches, a current day still being calculated, an old record left open, or elapsed days with no audit summary.

Hourly presence means only the local hour in which at least one audit snapshot was stored. It does not show the number of audited items in that hour. The view does not provide hourly filtering because ActiveHoursMask keeps only snapshot occurrence, without assigning audit counters to specific hours.


Settings for audit summary monitoring

The audit summary depends on several monitoring profile sections. In Automatic Audit, the editable switches are Hardware Audit and Software Audit. They decide whether core hardware and software inventory snapshots appear in the summary.

Next to those switches, the form shows Hardware and Software Audit Interval (minutes), but it is currently read-only. Additional settings, such as Maximum Hardware Audit Items per Class, Maximum Software Audit Items, WMI classes, and registry sources, are also informational. In Endpoint State Audit, Process Audit, Services Audit, and Users and Sessions Audit are visible, but these switches are read-only. Peripheral Device Audit and Printer Inventory also appear as informational controls.

After changing editable switches, wait for the next daily inventory cycle. Then return to Audit - summary and check whether Audit Areas, Audit Types, Snapshots, and Audited Items increased or decreased.