How do you open clipboard monitoring?

Open the view from the application menu: Menu -> Monitoring -> Clipboard. It is designed for analysing clipboard operations such as copied text, files, images and audio, and for checking whether copied file items were associated with USB paths.

Use this view when you need to understand the scale of clipboard activity, compare ordinary text copying with file copying, check the amount of data moved through the clipboard or find days where activity clearly changed compared with earlier behaviour. Clipboard monitoring is especially useful when reviewing document work, file movement between folders and cases where the clipboard may be part of a data transfer path.

The page contains an Analytics Panel and a records table. The panel presents metrics, rankings, trends, comparisons, anomalies, hourly presence and data quality. One table row represents one monitoring day for one computer. After selecting a row, the application opens details for that day, workstation and employee, grouped by item type, file, text, data size, source, foreground application and active hours.


Daily table in clipboard monitoring

The table helps you quickly decide whether the clipboard was used mostly for text on a given day, or whether file activity also played a visible role. The default columns show the values that best describe event volume before you open every item in detail.

The main visible columns are:

  • Text Copies - the number of recorded text copy operations.
  • Copied Files - the number of files included in clipboard copying.
  • Text Length - the total length of copied text, if the agent was able to count it.
  • Copied Data Size - the total data size for files visible in the details.

After expanding the columns, you can also check USB data, the last copied file, the most common extension, image and audio copies, copy events, paste candidates, and the number of text lines and words. These fields help separate ordinary text operations from copying a larger set of files.

The search covers date, agent, computer, Windows user, active hours, file extensions, the last copied file name, recent extensions and text stored in the details. This makes it easier to reach a specific event even when you only know part of the file name or extension.


Analytics Panel for clipboard activity monitoring

The Analytics Panel aggregates clipboard usage for the selected time range. You can switch the analysis between day, week, month and a custom period, and calculate values as Total or Daily Average. Daily average mode is useful when you compare a short incident with a longer period of normal work.

The key metrics are:

  • Text Copies - how many times the clipboard contained copied text.
  • Copied Files - how many files were included in clipboard copying.
  • Unique copied files - how many different files appeared in the details.
  • Copied from USB - how many file items were linked to a USB path.
  • Copied Data Size - the total size of files recorded in clipboard details.
  • Computers and Employees - the data coverage for the analysed period.

The panel is easiest to interpret by reading file count together with data size. Many small files describe a different type of activity than one large package of data. If Copied from USB grows at the same time, move to USB rankings and file details.


Rankings in copied file monitoring

Rankings show which clipboard items appeared most often in the data and where activity was concentrated. In this view, a high ranking position is not automatically a problem. It may reflect normal document work, but it can also point to a file or device that deserves verification.

The panel includes:

  • Top Copied Files - files with the highest number of clipboard occurrences.
  • Top copied files by size - files ordered by copied data size.
  • Top USB copied files - items associated with USB paths.
  • File Extensions - the distribution of copied files by extension.
  • Top Applications - foreground applications connected with clipboard events.
  • Top Computers and Top Employees - places and people with the highest number of events.

A practical review usually starts with files and extensions. If normal documents dominate, check size and computer. If archives, unusual extensions or USB items appear high in the list, open the record details and review the file path, source device and application visible during the event.


Trends and hourly presence in clipboard monitoring

Trends show how clipboard activity changed across consecutive days. You can review text copies, copied files, unique copied files, USB data, text length, copied data size, and the number of computers and employees as separate series.

When reading trends, check:

  • whether the increase concerns text, files or mainly data size,
  • whether USB events are a single spike or repeat across several days,
  • whether the number of unique files grows faster than the number of operations,
  • whether the activity belongs to one computer or to a wider part of the organisation.

The Hourly Presence chart shows the share of analysed days in which the agent noticed clipboard activity during a specific local hour. It is not a count of copies, a count of files or an activity duration chart. A marked hour only means that clipboard usage was observed during that hour.


Comparisons in monitoring clipboard usage changes

Comparisons place the current range next to a reference period. In the Clipboard view, this is especially helpful when you want to separate a regular document-heavy workday from a sudden increase in file copying or an unusual growth in copied data size.

When analysing comparisons, look at:

  • an increase in Text Copies, which often points to intensive editing or administrative work,
  • an increase in Copied Files, because it may show documents being moved through the clipboard,
  • an increase in Unique copied files, which suggests a broader range of items,
  • an increase in Copied from USB, especially when new computers are involved,
  • an increase in Copied Data Size, because one large file can matter more than many small operations.

If the comparison shows a large jump, first identify the metric behind it. Then check file rankings by count and size. The record details will finally show the file name, path, source device and application in which the clipboard was used.


Anomalies in clipboard and data copy monitoring

Anomalies highlight situations where clipboard usage clearly differs from previous behaviour or exceeds thresholds set for file count and data size. This section is worth checking before manual review of all records, because it quickly narrows the list of days that need attention.

The anomaly mechanism in this view includes:

  • Clipboard copy activity increased significantly - when the current copy count is much higher than in the comparison period.
  • High clipboard file copy count - when the daily record contains many files copied through the clipboard.
  • Large clipboard copied data size - when the data size in details exceeds the threshold for a large copy.

Anomaly evidence can include current and baseline clipboard copies, clipboard copy increase, file copy count, copied file count, last copied file and copied data size. For large data volumes, start with the file and path; for volume increases, start with the computer and employee.


Record details in clipboard item monitoring

After you click a record, the application shows clipboard items aggregated for one day and one computer. Details can contain separate rows for files and summary rows for text, image or audio content. This lets you see not only the number of operations, but also the data type and work context.

In the details table, check:

  • clipboard content identification: item, item type, file type and extension.
  • copy scale: Copies, data size, files copied from USB and copied files from details.
  • file context: USB, source device, file path, file name and directory.
  • program context: Application, foreground window and foreground executable path.
  • technical event data: operation type, content type, clipboard format, detection source, source and source type.
  • time and user frame: first seen, last seen, active hours and Windows user.

Hourly filtering is not available for clipboard usage details, because the active-hours mask stores only event presence and does not assign clipboard counters to specific hours. Treat details as a daily item summary, not as an hourly log of every copy operation.


Data quality in clipboard usage monitoring

The data quality section shows whether daily summaries have consistent clipboard details. This matters because a record may contain copy counters, but without details it is harder to determine which files or content types produced the result.

In the panel you can see:

  • Detail Coverage - what share of records has available clipboard details.
  • Records Without Details - days where clipboard data is visible but the item list is missing.
  • Current Partial Records - current-day records that may still be aggregated.
  • Open Historical Records - older clipboard entries left without closure.
  • Invalid Details - cases where the clipboard item list has a damaged structure.
  • Days Without Data - missing days in the analysed range, with no clipboard data received.

If a warning appears only for the current day, it can usually come from processing that is still in progress. If it concerns closed days, check the agent status, clipboard monitoring settings, the local queue and data export to the backend.


Clipboard monitoring settings

Clipboard usage is controlled through Monitoring Profiles. The agent applies profile settings only after it downloads the current configuration to the computer. For this view, settings from the file and clipboard areas matter, but only editable options are described here.

For the Clipboard view, the most important settings are:

  • Clipboard Monitoring - enables collection of clipboard activity data.
  • File Transfer Monitoring - the general file transfer option; it is needed when the clipboard should also be analysed as a file movement channel.
  • Clipboard File Transfer Monitoring - allows the agent to include clipboard activity in file transfer data.
  • Clipboard File Transfer Correlation - links clipboard events with potential file transfer operations.
  • Clipboard Correlation Window (seconds) - defines the time window in which events may be associated; in settings, the value is limited to 5-600 seconds.

If you only care about the number of text copies, Clipboard Monitoring is the key option. If you analyse files and possible data movement, also review transfer and correlation settings. After changing a profile, return to the view after the next monitoring day and compare copied files, USB data and copied data size.