How to open blocked application monitoring?

You can open the view from the application menu: Menu -> Monitoring -> Blocked Applications. It is used to review situations where Codenica Insight Agent detected an attempt to run a program covered by an application blocking rule and saved that blocking event in monitoring data.

This view helps the administrator answer practical questions: which applications are blocked most often, which rule was triggered, on which computer the attempt appeared, whether the user repeated the launch and whether the agent successfully stopped the process. It is not a regular application usage report, but a security and policy enforcement view.

At the top there is the Analysis Panel, where you can change the analysis period, calculation mode and tabs with rankings, trends, comparisons and anomalies. Below the panel there is a table of records. In this view one record means one monitoring day for one computer. After clicking a record, the application shows blocking details from that day, split by applications, processes, rules and matched values.


Record list in blocked application monitoring

The table shows daily blocking summaries for computers covered by monitoring. The default columns are selected so that the scale of events and the most important context are visible immediately: how many times applications were stopped, which application family dominated, which process appeared most often and which rule triggered blocking.

The most important columns in this view are:

  • Blocked - the number of saved blocking events for a given day and computer.
  • Application Family - the application group or name that appeared most often in the record.
  • Process - the process linked to the blocked application.
  • Most Triggered Rule - the rule that most often led to blocking.
  • User Attempts - the number of launch attempts or repeated actions on the user side.
  • Blocked Processes - the number of processes the agent had to block or terminate.
  • Last Executable Path, Last Matched Value and Last Match Type - diagnostic data useful when checking why a rule matched.

Search covers not only date, computer and user, but also application names, rules, processes, file paths, matched values and details stored in the record. This makes it easier to find a specific block even if you only know part of a program name or path.


Analysis panel in blocked application monitoring

The analysis panel collects table data and presents it for the selected date range. You can analyze a day, week, month or a custom period. Two calculation modes are available: Total, meaning the result for the whole range, and Daily Average, which recalculates values per analysis day.

The panel indicators describe the scale and reach of blocking:

  • Blocked - the total number of application blocks.
  • Unique Applications - the number of different applications or application families covered by blocking.
  • Rule Count - the number of rules involved in blocking.
  • Computers - the number of computers where such events appeared.
  • Employees - the number of employees linked to records, if the system could assign data to a user.

A useful way to read the panel is to compare the number of blocks with the number of applications and computers. Many blocks for one application may mean one problematic program or repeated launch attempts. Many unique applications across many computers suggest a broader environmental change or rules that are too broad.


Rankings in blocked application monitoring

Rankings show where blocking is concentrated. In this view, a high result usually means something worth checking, but it does not always mean a configuration error. Sometimes a rule works correctly and shows a real attempt to run software the organization does not allow. At other times, a large number of blocks points to a rule that is too general.

The panel includes the following rankings:

  • Top Blocked Applications - applications or application families with the highest number of blocks.
  • Top Blocking Rules - rules that most often stopped applications.
  • Top Employees by Blocked Applications - users linked to the highest number of events.
  • Top Computers by Blocked Applications - workstations where blocks appeared most often.

It is best to read rankings together. If the same application, rule and computer appear at the top, the issue is probably local. If a high position spans many computers, check the rule itself, its match type and the value that triggers blocking.


Trends and blocking hours in application monitoring

Trends show how blocks changed across the days. The Blocked chart helps notice a sudden increase in stopped applications, while Unique Applications, Rule Count, Employees and Computers help decide whether the issue is isolated or spread out.

In practice, check:

  • whether the increase in blocks appeared after changing a monitoring profile or adding a new rule,
  • whether the number of unique applications grows together with the number of blocks,
  • whether blocks concern many computers or one workstation,
  • whether the employee count is growing or the issue is tied to a single user.

The separate Hourly Blocking Presence chart shows the percentage of monitored days in which at least one block occurred during a given local hour. It is not the number of blocks or the duration of an event. A marked hour only means that a blocked application was observed during that hour.


Period comparisons in blocked program monitoring

The comparisons tab compares the current period with a previous range of similar length. In blocked application monitoring this is especially useful after policy changes, because the number of blocks alone does not say whether the situation is normal or something new has just started.

When reading comparisons, look at several signals:

  • an increase in Blocked may mean more real attempts to run prohibited programs or a new rule that started catching more cases,
  • an increase in Unique Applications shows that blocking covers more programs,
  • an increase in Rule Count may mean broader policy coverage or several rules matching similar cases,
  • an increase in computers or employees shows that the topic no longer concerns a single workstation.

If the number of blocks jumps after introducing new policies, do not assume a failure immediately. First check rule and application rankings, then record details. Often the matched value and match type are what reveal whether blocking works as intended.


Anomalies in blocked application monitoring

Anomalies point to situations that need attention faster than a regular table review. The system analyzes both growth in blocking compared with the previous period and individual records with many user attempts or problems with successful process termination.

The view can detect, among other things:

  • a significant increase in application blocks - when the current period has many more blocks than the comparison period,
  • repeated attempts to run a blocked application - when a user or computer repeatedly hits the same block,
  • process termination failures - when the agent tried to stop a process but some attempts failed,
  • a new frequently blocked application - when a program was absent in the previous period and now appears repeatedly.

Each anomaly contains context: date, computer or application, current value, reference threshold, change and evidence data, such as application name, rule, number of user attempts or failure share for process termination. Start with high-severity anomalies related to enforcement, because they may indicate an agent permission issue or a specific type of blocked application.


Record details in application blocking monitoring

After clicking a record, the application shows details for one day and one computer. This is where you can see which application was blocked, which process was launched, which rule matched and which value was detected. Details are therefore the best place to check whether the block comes from a correct policy or from a rule that needs refinement.

Details include, among other things:

  • Application, Process and Application Family, identifying the blocked program,
  • Rule, Rule ID, Match Type and Matched Value, explaining why the program was stopped,
  • Blocked, Blocked Share, User Attempts and Blocked Processes, helping assess the event scale,
  • Executable Path, First Seen, Last Seen and Active Hours, useful for technical diagnostics.

Hourly filtering does not split blocking counters into specific hours, because the active-hours mask stores event presence, not the number of blocks in each hour. Treat details as a daily event summary, not a minute-by-minute blocking log.


Data quality and freshness in application blocking monitoring

Data quality and freshness sections show whether the results visible in the panel have complete details. In the Blocked Applications view this matters because a daily block count can exist even when the detailed list of applications or rules has not yet been saved correctly.

Pay attention to the following information:

  • Details Coverage - shows what share of records has detailed data.
  • Records Without Details - indicates records where blocks exist but the application or rule list is missing.
  • Live Partial - means current-day records that may still be aggregating.
  • Historical Open Records - shows older records that were not closed.
  • Invalid Details - informs about a problem with the detailed data structure.
  • Missing Data Days - shows days in the selected range where there is no blocked application data.

Freshness tells you when the view was generated, what the newest record is and whether it includes the current day. If you see quality warnings, first check whether the issue concerns only the current day or also closed historical records.


Blocked application monitoring settings

Application blocking is configured in Monitoring Profiles, in the applications tab. Profile changes are saved in the agent configuration and start working after assigned computers receive the new configuration. If a profile is not assigned separately, the agent uses the default profile.

The most important settings for this view are:

  • Application Blocking - enables or disables enforcement of application blocking rules.
  • Application Family Blocking - allows blocking not only a single process, but also an application family when the agent can recognize it.
  • Application Block Rules - the list of rules that define what should be blocked.
  • Rule Enabled - lets you temporarily disable a single rule without removing it from the profile.
  • Name - a descriptive rule name visible later in reports and rankings.
  • Value - text, process, path or another fragment the rule should match.
  • Match Type - the way an application is recognized, for example by process name, file name, path fragment or application family.
  • Excluded Process Names - a list of processes that application monitoring should not treat as typical user programs.

When creating rules, use values that are as specific as possible. A match that is too broad can generate many blocks and make panel analysis harder. After saving changes, it is worth returning to this view after one or several monitoring days to check whether application and rule rankings show the expected result.