How do you open file transfer monitoring?
Open the view from the application menu: Menu -> Monitoring -> Files - transfers. It is used to analyse file movement recognized by the agent, including situations where a file was downloaded, uploaded, moved to media, copied through the clipboard, sent as an attachment or linked with printing.
Open this view when you need more than ordinary file activity and want to understand the direction of data movement. File transfer monitoring helps you see which files were transferred most often, whether outbound transfers dominated, how large the total transfer size was and whether a channel appeared that had not been present in the observed period before.
The page consists of an Analytics Panel and a records table. The panel shows transfer counters, channels, directions, file rankings, trends, comparisons, anomalies, hourly presence, data quality and aggregation freshness. Each table row describes one daily transfer record from one computer. After selecting a record, the application opens details for the workstation and employee, broken down by files, channels, directions, source and target paths, devices, domains, applications, emails, printers and detection confidence.
Daily table in file transfer monitoring
The daily table lets you quickly assess the scale of data movement without opening every file separately. The first columns show how many transfers were detected, their size and whether outbound or inbound movement was stronger.
The key fields visible in the table are:
- Transfers - number of recognized transfers in the daily record.
- Transfer Size - sum of data associated with transfers.
- Outbound Transfers - file movement from the computer to an external target or channel.
- Inbound Transfers - file movement arriving on the monitored workstation.
After expanding columns, you can also check the most transferred file, channel, transfer type, last direction, USB transfers, web transfers, email transfers, clipboard transfers, print transfers, large file transfers, candidate transfers, confirmed transfers, last file, last source, last target, domain, URL or title, application, process, printer and detection source.
Search works across date, agent, computer, Windows user, active hours, file names, channels, directions, paths, domains, URLs, devices, applications, processes, printers, email senders and recipients, and detail content. If you know a path fragment, a domain or an email subject, you can quickly filter records that need review.
Analytics panel in file movement monitoring
The analytics panel collects transfers from the selected time range. You can switch analysis to day, week, month or custom range, and read results as Total or Daily Average. Use the daily average when the period under review is short and the reference range is much longer.
The main panel metrics are:
- File Transfers - the primary counter of detected file movement.
- Outbound Transfers - number of transfers that may indicate sending or taking data out.
- Inbound Transfers - number of transfers where files arrived on the computer.
- Transfer Size - total data volume connected with file movement.
- Computers and Employees - scope of workstations and users included in the analysis.
In this view, transfer count should be read together with size. A small number of transfers with a large size can matter more than many tiny entries. If outbound share increases, move to file and channel rankings, then open the record with the largest movement.
Rankings in transfer channel monitoring
Rankings show which files, channels and directions built the movement in the analysed period. They let you start from the most significant areas instead of manually reviewing all daily records.
The panel includes, among others:
- Top Transferred Files - files with the highest number of transfers and an additional size value.
- Transfer Channels - movement distribution by channel, such as USB, web, email, clipboard or printing.
- Transfer Directions - split into outbound, inbound, internal or unrecognized movement.
- File Extensions - file types appearing most often in transfers.
- Top computers and top employees - workstations and accounts linked with the highest transfer count.
If USB is at the top of the ranking, check the source or target device in details. For the web channel, domain, URL or title will matter. For email transfer, review sender, recipient and subject, because these fields help decide whether the movement belongs to a normal business process.
Trends in outbound and inbound transfer monitoring
Trends show how file movement changed across consecutive days. Separate series cover file transfers, outbound transfers, inbound transfers, transfer size, computer count, employee count, transfer channels, transfer directions and file extensions.
When reading trends, pay attention to:
- whether the increase concerns transfer count, data size or both at once,
- whether an outbound transfer spike appears after a period without similar movement,
- whether channel changes point to new USB, web, email, clipboard or print usage,
- whether extension growth means new file types in movement,
- whether the pattern concerns one computer or several workstations at the same time.
The Hourly Presence chart shows the share of days in the selected range where at least one transfer appeared at a specific local hour. It is not a transfer counter and not a sum of transferred bytes. A marked hour only means that movement was present at that time.
Comparisons in file movement monitoring
The comparison area places the current range next to reference data. In the Files - transfers view, it is especially useful for quickly answering whether data movement grew, changed direction or moved to another channel.
When analysing comparisons, check:
- an increase in File Transfers, because it shows the general change in movement scale.
- an increase in Outbound Transfers, especially when this movement was low in the previous period.
- a change in Transfer Size, because one large file can be more important than a long list of small transfers.
- the difference in computer and employee counts, to identify whether the event is local or broader.
- changes in channels and directions, because they often point to the source of an unusual result.
If the comparison shows a clear increase, do not start with the chart alone. First establish whether outbound movement dominated, then check channel and extension, and only after that move to file details. This order reduces the risk of reading ordinary synchronization as an incident.
Anomalies in data transfer monitoring
Anomalies in this view focus on situations that may indicate unusual data movement. The system compares periods, checks channels and looks for transfers that exceed configured count or size thresholds.
The anomaly mechanism includes:
- Outbound file transfers increased significantly - when the current outbound transfer count clearly exceeds the comparison period.
- high USB transfer volume - when the number of USB transfers or their size crosses the rule threshold.
- Large file transfer detected - when a single file or transfer candidate exceeds the configured size threshold.
- New file transfer channel has a high share - when a channel absent from the baseline period starts to account for a large part of transfers.
Anomaly evidence may include current outbound transfers, baseline outbound transfers, minimum percent increase, USB transfers, USB transfer size, file name, channel, transfer size, transfer count and share percent. For a large file, start with source and target paths; for a new channel, check whether its use was planned.
Record details in transferred file monitoring
After clicking a record, the application shows transfers aggregated for one day and one computer. Repeated traces of the same file are combined, so a single detail row can show transfer totals, size and the latest known source and target context.
In the details table, check:
- file identification: file, extension, transfer name, item key and identity key.
- data movement: Direction, channel, transfer type, transfers, transfer size and transfer share.
- source-target context: source path, target path, source device and target device.
- application channels: domain, URL or title, application, process, window title and printer.
- email context: email sender, email recipient and email subject.
- detection quality: average confidence, minimum confidence, maximum confidence, confidence observations and confirmed transfers.
- time context: first detection, latest detection and active-hour markers.
File transfer details cannot be narrowed by hour because the active-hours mask records presence only. It does not assign transfer counters or sizes to individual hours, so details should be treated as a daily register of transferred files.
Data quality in file transfer monitoring
The data quality section tells you whether daily records have complete transfer details. This matters because the transfer counter alone does not explain which file was moved, which path it followed and whether the system has enough context to assess the event.
In this report area, check:
- Details Coverage - share of records with an available transferred file list.
- Records Without Details - days where a summary exists but there is no file-level breakdown.
- Current Partial Data - current records that may still be aggregated.
- Historical Open Records - older days left without full closure.
- Invalid Details - cases where the transfer details JSON structure is damaged or unreadable.
- Missing Data Days - missing days in the selected range.
A warning on the current day usually means that the agent or backend is still finishing aggregation. If the problem concerns closed dates, check agent status, the transfer monitoring profile, channels enabled in settings and whether data export to the backend works correctly.
File transfer monitoring settings
Data in the Files - transfers view depends on Monitoring Profiles. When a profile is saved, the agent must receive the fresh configuration on the computer; only then will it affect the next daily records. For this view, editable options from file, USB, clipboard, print and web sections matter.
The most important settings are:
- File Transfer Monitoring - the main switch for data visible in this view.
- File Transfer Deduplication (seconds) - limits repeated counting of similar transfers within a short time window.
- Large File Transfer Threshold (MB) - defines from what size a file should be treated as a large transfer.
- Download, web and email channels: Downloads File Transfer Monitoring, Web Upload Transfer Monitoring and Email Attachment Transfer Monitoring decide which of these traces enter the view.
- External media: USB File Transfer Monitoring and Removable Drive File Transfer Monitoring affect data related to devices connected to the computer.
- Clipboard: Clipboard File Transfer Monitoring, Clipboard File Transfer Correlation and Clipboard Correlation Window (seconds) help connect clipboard activity with a file transfer.
- Print File Transfer Monitoring - enables transfer data associated with printing.
If an expected channel is missing in the view, first check whether File Transfer Monitoring is active. Then verify the switch for the specific channel, such as USB, web, email, clipboard or printing. For clipboard, also remember the Clipboard Monitoring setting, because without clipboard data the transfer correlation will not have full context.
