How do you open file activity monitoring?
Open the view from the application menu: Menu -> Monitoring -> Files. It is used to analyse file events recorded by the agent: creations, changes, deletions, renames and events whose type was not recognized clearly.
Open this view when you want to see which files were touched most often, where work concentrated in the folder structure, which extensions appeared most frequently and whether file activity followed a normal work rhythm or looked more like cleanup, a bulk change or data removal. File monitoring is a useful starting point before analysing transfers, documents and USB activity.
The screen combines an Analytics Panel with a table of daily records. The panel walks through action counters, file rankings, directory and extension breakdowns, trends, comparisons, anomalies, hourly presence and detail quality. Each table entry is a daily file activity record from one computer. After selecting an entry, the application opens details for that workstation and employee, with files, actions, paths, size, detection source and activity hours.
Daily table in file monitoring
The table shows a daily summary of file activity. Its first columns answer the basic question: did the day mainly contain creating, modifying, deleting or renaming files?
The key columns visible immediately are:
- Unique Files - the number of different files recognized in activity.
- Created - the number of file creation events.
- Changed - the number of file modification events.
- Deleted - the number of file deletion events.
- Renamed - the number of rename events or moves visible as path changes.
After expanding columns, you can check file activity, size, most active file, most common action, extension, action shares, last file, last directory, full path and old path. These values help separate a single file save from a larger series of changes in a directory.
Search covers date, agent, computer, Windows user, active hours, file names, extensions, actions, directories, full paths, old paths and detailed data content. If you know part of a path, a file name or an extension, you can quickly narrow the list to the relevant days.
Analytics Panel in file event monitoring
The Analytics Panel aggregates data from the selected time range. You can switch analysis between day, week, month and a custom range, and read values as Total or Daily Average. Daily average is useful when the compared periods have different lengths.
The main panel metrics are:
- Unique Files - the number of different files visible in details.
- the file action breakdown: created, changed, deleted and renamed.
- File Activity - the total number of file events in the analysed period.
- File Activity Size - the sum of sizes associated with file activity.
- Computers and Employees - the data scope included in the analysis.
A good habit is to read event count together with size. High activity with small size can mean many minor saves, while fewer events with large size may point to work on heavier files. If deletion share is high, go straight to details and the action ranking.
Rankings in file and directory monitoring
Rankings show exactly where activity was concentrated. Instead of opening every record, you can start with files, actions, extensions and directories that had the largest share in the selected period.
The panel includes:
- Top Files - files with the highest number of events.
- File Actions - activity distribution by operation type.
- File Extensions - extensions most often appearing in events.
- Directories - places in the file system where activity was highest.
- Top Computers and Top Employees - workstations and people connected with the largest number of events.
If a user directory appears high, check extensions and actions. If a system or application directory dominates, the result may come from a program, update or background process. Only the combination of directory, action and last path gives enough context to judge whether events are normal for that computer.
Trends and hourly presence in file monitoring
Trends show how file activity changed day by day. Separate series cover unique files, creations, changes, deletions, renames, total file activity, activity size, computers and employees.
When analysing trends, check:
- whether the event increase concerns one action or all operation types at once,
- whether activity size grows together with event count,
- whether deletions appear as a single spike or as a repeated pattern,
- whether renames are connected with directory changes or old paths.
The Hourly Presence chart shows local hours in which file activity appeared on analysed days. It is not an event counter or a sum of file size. A marked hour only tells you that the agent recorded at least one occurrence of activity at that time.
Comparisons in monitoring file changes
The comparison tab places the current period beside a reference period. In the Files view, it is especially helpful when you want to quickly assess whether event count increased, operation type changed or activity moved to other file types.
When comparing, check:
- an increase in File Activity, because it shows the overall scale change in events,
- an increase in Deleted, especially when deletions were previously low,
- a change in File Activity Size, because it can reveal work on larger files,
- the difference in unique file count, which shows whether activity was spread out,
- the change in computers and employees, to determine whether the pattern belongs to one person or a wider area.
If the comparison shows a clear increase, first identify the dominant action. Then check file and directory rankings, and finally open the record with the highest activity. That is where you see full path, old path and detection source.
Anomalies in file activity monitoring
Anomalies point to situations where file activity exceeds the usual level or where deletions, size or a new extension take an unusual share. This section is useful for a quick risk review before manually entering many records.
The anomaly mechanism includes:
- File activity increased significantly - when event count in the current period is clearly higher than in the comparison period.
- File deletion volume increased significantly - when daily or period deletions grow more strongly than typical activity.
- Large file activity volume detected - when a specific file accumulates a large activity size.
- New file extension has a high activity share - when an extension absent earlier begins to dominate current events.
Anomaly evidence can include current and baseline file events, current and baseline deleted files, minimum percent increase, file events, file activity size, file path, extension and activity share. For deletions, start with the file list and directory; for a new extension, check whether it is expected in the team's work profile.
Record details in file operation monitoring
After clicking a record, the application shows file activity details aggregated for one day and one computer. Repeated events for the same file are combined, so a detail row shows the action totals and the latest known file context.
In the details table, check:
- file identification: file, extension, directory, full path and old path.
- operation type: Action, created, changed, deleted, renamed and unknown.
- scale: File Activity, size and activity share.
- source context: detection source, category, source, source type and item key.
- timing and account context: first seen time, last seen time, active-hour markers and Windows user.
File activity details do not support hourly filtering because the active-hours mask stores only event presence. It does not split creation, change, deletion or size counters into individual hours, so treat details as a daily view of file activity.
Data quality in file activity monitoring
The data quality section helps assess whether daily summaries have consistent file details. This matters because the event count alone is not enough if information about paths, actions or directories is missing.
In this part of the panel, check:
- Detail Coverage - the share of records with an available file list.
- Records Without Details - days where activity counters exist but detail items are missing.
- Current partial data - current-day entries that may still be waiting for full aggregation.
- Open historical records - older records that remained open.
- Invalid Details - cases of damaged or unreadable detail data structure.
- Days without data - missing days in the selected time range.
A warning on the current day often comes from ongoing aggregation. When the message appears for already closed dates, check agent status, monitoring profile, watched folders and extensions, and whether export to the backend is working correctly.
File activity monitoring settings
Files view data depends on settings in Monitoring Profiles. After a profile change, the new configuration must reach the agent on the computer before it affects later records. For this view, editable options from the file activity section matter.
The most important settings are:
- File Activity Monitoring - enables collection of file events shown in this view.
- Watched File Extensions - defines which file types should be observed; the list affects which extensions appear in the table, rankings and details.
- Watched User Folders - indicates user profile folders covered by observation, by default Desktop, Documents and Downloads.
If expected files are missing from the view, start by checking whether File Activity Monitoring is active in the profile. Then compare the missing extension and directory with profile settings. Document Insight is in the same settings section, but it mainly affects the Documents view, not the basic file activity register.
