How do you open geolocation monitoring?

Open the view from the application menu: Menu -> Monitoring -> Geolocation. It analyses the network location of computers using IP addresses recorded by the agent and enriched with geographic data such as country, region, city, time zone, provider and coordinates.

Use this view when you want to verify whether a computer worked from an expected location, whether a new country appeared, whether addresses were public, private or local, and whether geolocation resolution is complete enough for further analysis. Geolocation monitoring is especially useful for remote work, business travel, VPN networks and cases where an IP location can explain other events visible in monitoring.

This screen combines an Analytics Panel with a records table. The panel shows unique locations, location changes, geolocation resolution, private or local IP share, countries, cities, rankings, trends, comparisons, anomalies, hourly presence and detail quality. Each table row describes one monitoring day for one computer. After selecting an entry, the application opens that day’s workstation and employee details, with locations, IP addresses, IP types, resolution statuses, coordinates, provider, resolution message and active hours.


Daily table in device geolocation monitoring

The daily table shows the last known location context for a computer on the selected day. It helps you quickly notice whether the record has a resolved location, whether it is based on a private IP address and whether the location changed during the day.

The most important columns visible immediately are:

  • Last Location - last location label stored for the record.
  • Resolution Status - information whether geolocation was resolved as Resolved or Unresolved.
  • Location Changes - number of location changes detected on that day.

After expanding columns, you can also check IP type, IP address, country, city, provider, region, country code, time zone, latitude and longitude, first location, private or local IP, Resolved status and geolocation error. These fields help separate a real place change from a local address, VPN visibility or missing resolution data.

Search covers date, agent, computer, Windows user, active hours, last IP address, country code, country, region, city, time zone, first and last location, provider, error message and detail content. In practice, a city, country, IP address or provider fragment is usually enough to narrow the list quickly.


Analytics panel in IP location monitoring

The analytics panel aggregates geolocation data from the selected interval. You can view a day, week, month or custom date range, and switch values between Total and Daily Average modes. The second mode is helpful when the compared periods contain a different number of monitored days.

The main panel metrics are:

  • Unique Locations - number of different locations recognized in the data.
  • Location Changes - number of transitions between locations in the analysed range.
  • Geolocation Resolution - percentage of observations for which a geographic location could be determined.
  • Private/Local IP - share of observations based on private or local addresses.
  • Countries and cities - number of recognized geographic areas.
  • Computers and employees - scope of workstations and users in the analysis.

When reading the panel, do not treat the location count alone as proof of movement. A high private or local IP share may mean that the agent worked inside an internal network or behind a VPN. Check resolution status first, then evaluate countries, cities and the number of location changes.


Rankings and distributions in computer location monitoring

Rankings show where geolocation observations appeared most often. They are a good starting point when you need to determine whether activity was concentrated in one place or spread across several countries, cities or providers.

The panel includes:

  • Top Locations - locations with the highest number of observations.
  • Top Countries - countries most often visible in the data.
  • Top Cities - cities linked with the largest number of observations.
  • Geolocation Resolution - distribution of Resolved and Unresolved statuses.
  • IP Types - distribution of Public and Private or local values.
  • Top computers and top employees - workstations and accounts with the highest number of observations.

If a private or local IP type appears high in the ranking, read it as a signal of limited geographic visibility, not as a precise location. If a new country or city dominates, open the record details and check the IP address, provider, coordinates, first seen time and last seen time.


Trends and hourly presence in geolocation monitoring

Trends show how location data changed day by day. Separate series cover unique locations, location changes, geolocation resolution, private or local IP share, countries, cities, computers and employees.

For geolocation charts, check:

  • whether growth in location count goes together with growth in location changes,
  • whether a drop in geolocation resolution appears at the same time as a rise in private or local IP addresses,
  • whether a new country or city appears once or repeats over several days,
  • whether the change affects one computer or a larger group of workstations,
  • whether employee count grows together with computer count.

The Hourly Presence chart shows the share of monitored days in which a geolocation observation appeared during a specific local hour. It does not mean time spent in a location or movement duration. A marked hour only says that the agent observed geolocation data at that time.


Comparisons in location change monitoring

Comparisons place the current range next to the reference period. In geolocation, they help verify whether the number of changes increased, whether new countries or cities appeared and whether resolution quality is similar to the previous period.

When analysing comparisons, check:

  • an increase in Location Changes, because it may indicate more frequent network switching, travel, VPN use or a change in work pattern.
  • a change in Unique Locations, especially when the computer was previously visible in only one place.
  • a decrease in Geolocation Resolution, because it limits the reliability of country and city interpretation.
  • an increase in Private/Local IP, which may point to internal network work or a tunneled connection.
  • differences in country, city, computer and employee counts, so you can estimate the scale of the pattern.

When the comparison exposes a clear jump, begin with the value that moved the most. Then check location and IP type rankings before opening record details. This makes it easier to separate an actual place change from a simple change in network visibility.


Anomalies in geolocation and IP type monitoring

Anomalies point to situations where location data differs from previous behaviour or has limited diagnostic value. This view does not judge the user’s physical presence in a place; it signals unusual location changes, new countries and IP resolution problems.

The anomaly mechanism includes:

  • Location changes increased significantly - when the current period has clearly more location changes than the comparison period.
  • New country detected - when a country not seen before appears in geolocation monitoring.
  • High share of unresolved geolocation records - when most observations cannot be assigned to a geographic location.
  • Only private or local IP addresses were detected - when data comes almost entirely from addresses that limit geographic resolution.

Anomaly evidence may include current and baseline location changes, minimum percent increase, country, observations, unresolved share, unresolved observations, private or local IP share and private or local observations. For a new country, check the employee and computer; for unresolved records, start with IP type and the resolution message.


Record details in IP location monitoring

After clicking a record, the application shows locations aggregated for one day and one computer. If the same location or IP address appeared many times, details merge observations and show the latest known location context.

In the details table, check:

  • location identification: location, IP address, IP type, item key and location key.
  • data status: Resolution Status, Resolved or Unresolved value and resolution message.
  • geographic data: country, country code, region, city, latitude, longitude and time zone.
  • resolution source: location provider and possible geolocation error.
  • observation scale: observations, private/local IP and resolution status.
  • record frame: first seen, last seen, active hours and Windows user.

Geolocation details cannot be narrowed with an hourly filter because the active-hours mask stores only observation presence. It does not assign location counters to individual hours, so treat details as a daily summary of IP locations, not as a precise movement timeline.


Data quality in geolocation monitoring

The data quality section helps assess whether daily records have complete and consistent geolocation details. This matters because IP location can depend on provider, VPN, proxy, company network and whether the address is public.

In this part of the panel, check:

  • Details Coverage - percentage of records where the location list can be opened.
  • Records Without Details - days with a daily geolocation result but no observation breakdown.
  • Current Partial Data - current-day entries that may still wait for aggregation to close.
  • Historical Open Records - older records left in an open state.
  • Invalid Details - cases where geolocation details cannot be read correctly.
  • Missing Data Days - date gaps in the selected monitoring range.

If the view contains many Unresolved or Private or local values, it does not necessarily mean an agent error. It often results from internal network work, VPN use or addresses that cannot be reliably assigned to a city. I did not find editable profile settings directly tied to geolocation for this view, so when problems appear, start with agent status, availability of network data and export of records to the backend.