How do you open USB audit monitoring?
Open the view from Menu -> Monitoring -> Audit - USB. This page is designed for checking the daily state of USB storage devices, meaning the automatic inventory of removable storage visible on computers. It is not a file copy history and it does not measure time spent using a device. It is a snapshot showing which USB devices the agent found on a given day and which technical parameters were saved.
Use this view when you want to check USB devices, connected devices, total size, total free space, free space percent, device status, serial number, model, vendor, drive, volume and policy decision. A USB audit helps you assess whether new portable storage appeared on computers, whether the capacity looks unusual and whether USB storage blocking recognized the device as expected.
The page consists of the analytics panel and the details section for the selected entry. The panel is described below because its cards, rankings and charts are read differently from a simple table. In this table, one entry represents the daily monitoring record for one machine. When you open a row, the application shows the details for that day for the selected computer and employee, split into individual USB devices and aggregated according to this view.
Daily table in USB inventory monitoring
The table is the first place to check quickly whether USB storage was detected on a computer and what its current state looks like. Rows are sorted from the newest dates, so the latest snapshots collected by agents usually appear at the top.
The default visible columns are:
- USB Devices - the number of detected storage devices in the daily record.
- Connected Devices - how many devices had a status indicating presence or mounting.
- Total Size - the combined capacity of USB storage shown in a readable unit.
- Free Space - the total available space on the detected devices.
The table configuration also contains supporting fields, including disconnected devices, blocked devices, allowed devices, devices with an unknown policy decision, free space percent, last model, last vendor, last product, last revision, last drive, last volume, last drive format, last drive type, last status, last device ID and last serial number. This lets you start with a simple overview and reveal more technical columns during incident analysis.
Analytics panel in USB storage state monitoring
The analytics panel uses the newest record for each computer in the selected date range. As a result, it does not count the same USB storage from multiple days as separate current devices. Instead, it builds the latest known state for the machines included in the filter.
The most important panel metrics are:
- USB Devices - the number of storage devices recognized in the latest snapshots.
- Connected Devices - devices with a ready, online, mounted or connected status.
- Total Size - the combined capacity of detected USB storage.
- Total Free Space - how much space remains available on those devices.
- Free Space Percent - the share of free space in the total capacity.
- Computers and Employees - the scope covered by the aggregation.
A high number of devices with only a few computers may point to workstations where different storage devices are often attached. A drop in free space is a signal to open the record details and inspect the specific device instead of judging the situation only from the panel total.
Rankings in USB model and capacity monitoring
Rankings show which storage devices, models and vendors appear most often in the selected period. For a USB audit, this is more practical than browsing many computers by hand, because recurring devices and the largest-capacity media become visible immediately.
In the rankings tab you can analyze:
- USB Devices - recognized storage devices counted by stable identity.
- USB models - model names read from the hardware identifier or operating system data.
- USB vendors - device manufacturers or vendors, if the agent could determine them.
- USB devices by capacity - devices ordered by size.
- USB devices by lowest free space - items that need a storage-space check.
- Computers and Employees - places where the audit found the highest number of storage devices.
When interpreting the ranking, remember that the system groups entries by serial number, device ID, item key or display name. That is why the ranking is useful for checking recurring devices in the audit, not for counting every single connection operation.
Trends in USB capacity change monitoring
Trends show how the daily USB storage state changed over time. Because the data has a snapshot nature, the charts are best read as an inventory history: whether devices appeared, whether total capacity changed and whether the share of free space is falling.
The available series include USB Devices, Connected Devices, Total Size, Total Free Space, Free Space Percent, Computers and Employees. Switch between series depending on the question you want to ask: device count explains scale, capacity explains the type of media, and free space points to possible storage exhaustion.
A sudden increase in total size may mean that a large flash drive or external disk was added. If the number of devices stays similar but free space percent falls, open the latest record details and find the storage device responsible for the change.
Comparisons in daily USB audit monitoring
The Comparisons tab places the current period next to the baseline period. In a USB audit, this is especially useful after changing storage rules, deploying new agents or reviewing the list of allowed devices.
In comparisons, pay attention to:
- USB Devices - whether the number of detected storage devices increased or decreased.
- Connected Devices - whether more devices were present in the latest snapshots.
- Total Size - whether larger-capacity devices appeared.
- Total Free Space and Free Space Percent - whether storage devices are becoming more filled.
- Computers and Employees - whether the difference comes from a changed data scope.
If the change concerns capacity only, start with the ranking of devices by capacity. If the number of connected devices increases, check computers and employees to identify where the audit found the strongest concentration of storage media.
Anomalies in USB device and access policy monitoring
Anomalies in this view look for changes that may indicate a new device, a different capacity, low free space or a USB storage blocking response. The mechanism compares the newest computer snapshots with the baseline period and also checks the device details saved in the record.
The view can report:
- USB device count changed significantly - the current device count differs from the baseline value.
- USB storage capacity changed significantly - the total size exceeded the configured change threshold compared with the previous period.
- USB storage free space is low - a device has a low percentage of available space.
- Blocked USB storage device detected - at least one device was marked as blocked by policy.
- USB policy decision is unknown - the rule exists in the mechanism, but it is disabled by default.
In anomaly evidence, check Current USB Device Count, Baseline USB Device Count, Current USB Storage Size, Baseline USB Storage Size, Minimum Percent Change, USB Device, Drive Name, Serial Number, Free Space, Total Size, Free Space Percent and Policy Decision. These fields help separate a real hardware change from a different Windows detection result for the same storage device.
Record details in daily USB list monitoring
After you click a record, the application shows the list of USB devices collected for one computer and one day. Details are sorted by device name, drive and serial number, so it is easy to connect a visible storage device with its technical identifier.
The details include:
- USB Device - the display name built from model, volume, drive, serial number or identifier.
- Drive and Volume - the drive letter and label, if available.
- Drive Type, file system, drive format and device status.
- Size, free space and free space percent.
- Serial Number, device ID, model, vendor, product and revision.
- First seen, last seen, active hours, item key, active hours mask, day start and day end.
- Policy, meaning the decision associated with the device: allowed, blocked or unresolved.
If several detail rows look similar, check the serial number and device ID. The parser tries to merge entries for the same storage device, but when system data is incomplete, stable identifiers remain the best reference point.
Data quality in USB snapshot monitoring
The data quality section tells you whether the details list matches the daily summary. For a USB audit this matters because the number of devices, policy statuses and total capacity should correspond to the items saved in the record details.
Quality messages may indicate that some details fall outside the day boundaries, the current day is still being aggregated, a closed record has no details or the device list does not match the summary counters. If such a warning appears, do not treat the result as the final storage list. Check the date range, agent state and the last processing time first.
The hourly presence chart shows the percentage of monitored days in which the USB audit snapshot was saved during a given local hour. It does not represent the number of devices or the time spent using storage media. Hour filtering is not available because ActiveHoursMask stores only snapshot presence, without assigning USB counters to individual hours.
Settings for USB audit monitoring
Data in the USB audit view is connected with the USB section of the monitoring profile settings. The most important editable switch is USB Monitoring. When it is enabled, the agent can collect information needed for the daily storage inventory. When it is disabled, the view stops receiving full USB storage data.
The same section contains USB storage policy settings. You can edit the switch named USB Storage Blocking, choose the behavior in USB Storage Blocking Mode, and maintain the Allowed USB Storage Devices list. The mode can work as Block unknown devices or Block all except allowed devices, while the allowed-device list stores identifiers for storage devices that should remain accepted by the policy.
The form also shows read-only technical controls for logical USB disks, PNP disk detection, volume-change events, periodic seen events, seen-event interval, policy debounce and polling fallback. In the current configuration these fields describe how the agent works, but they are not options for manual change. After changing editable settings, return to the view after the next daily snapshot and check device count, policy decisions and record details.
