How do you open print monitoring?

Open the view from the application menu: Menu -> Monitoring -> Printing. It is used to review print activity recorded by the agent on employee computers. In one place you can see physical prints, physical printed pages, prints to file, most used printers, most printed documents, print sources and information about cancelled or failed prints.

Use this view when you want to check whether printing increased in a selected period, which devices carry the heaviest load, whether documents were saved as files, how often the agent uses the PDF fallback and whether print usage details are complete. Print monitoring also helps separate ordinary office work from cases where a sudden number of pages or large files are sent through the print process.

The layout pairs an Analytics Panel with the daily record grid. The panel organises metrics, rankings, trends, comparisons, anomalies, hourly print presence and data quality. The table stores daily results: a single entry represents one monitored workday for one computer. Selecting a row opens workstation and employee details for that day, with documents, printers, print output type, status, page counters, data size, file path, source and detection time.


Daily table in computer print monitoring

The daily table gives a short view of print activity for a computer on a specific date. Its first columns help you quickly decide whether the day was dominated by physical prints, printing to file or only a few jobs with a small page count.

The immediately visible columns are mainly:

  • Physical Prints - the number of confirmed prints sent to a physical printer.
  • Physical Printed Pages - the total pages assigned to physical prints.
  • Prints to File - jobs recognised as output saved to a file.
  • Most Used Printer - the printer that dominates the daily record.

After expanding columns, you can also review file output pages, most printed document, print data size, last printer, last document, last user, last source, last message, last file path, print jobs, all completed print pages and unknown page counts. These fields are useful when the print count alone does not explain the scale, but a large data size or file path suggests what was actually processed.

Search covers date, agent, computer, Windows user, active hours, printer names, documents, sources, messages, file paths and detail content. In practice, the fastest filters are usually a printer name fragment, document name, user account or part of an output path.


Analytics panel in print usage monitoring

The analytics panel collects data from the selected range and lets you switch between day, week, month and custom dates. Total shows the combined result for the period, while Daily Average is useful when compared ranges have different numbers of workdays or different data coverage.

The main panel metrics include:

  • Physical Printers Used - the number of printers where confirmed printing was detected.
  • physical prints and physical printed pages, which describe the basic workload handled by printers.
  • Prints to File - cases where the print output was linked with a file.
  • Print Data Size - the total amount of data sent through print events.
  • average values per printer and per physical print, useful for assessing device usage intensity.
  • cancelled and failed prints, which can signal queue, driver, permission or document problems.

When reading this panel, do not rely only on the number of jobs. A small set of prints may still contain many pages, and a single document may have a large data size. In print monitoring it is better to read print count, pages, size and completion statuses together instead of judging activity from one metric.


Rankings in printer and document monitoring

Rankings show which elements contribute the most to the selected period. In this view the point is not only to name the most used printer, but also to separate paper printing from file output and to see whether activity is concentrated on one computer or employee.

The panel includes, among others:

  • Most Used Printers by Print Count - printers with the highest number of confirmed physical prints.
  • Most Used Printers by Printed Pages - devices that handled the largest page volume.
  • Top Print-to-File Documents - documents and paths recognised in prints to file.
  • Top Computers by Print Activity - workstations with the highest print activity.
  • Top Employees by Print Activity - accounts with the highest print activity.
  • rankings by printed pages and by prints to file, useful for separating paper load from file-based output.

If a printer leads by print count but not by pages, it may be handling many short documents. If the page ranking is high, check whether a single long document is responsible. For prints to file, look at document name, file path and print source, because these fields usually explain the event context best.


Trends and active hours in print monitoring

Trends show how print activity changed day by day. Separate charts cover physical prints, physical printed pages, prints to file, print data size, cancelled prints, failed prints, computers and employees.

When analysing trends, check:

  • whether growth in physical prints is accompanied by growth in page count,
  • whether print data size rises without a similar increase in job count,
  • whether prints to file are a one-off event or repeat across multiple days,
  • whether cancelled and failed prints appear in the same date range,
  • whether higher activity belongs to one computer or a wider group of workstations.

The Hourly Print Presence chart shows the percentage of monitored days where the agent noticed print activity during a given local hour. It is not a counter of jobs, pages or data size. A marked hour only means that at least one print usage event occurred in that hour.


Comparisons in print volume monitoring

The comparisons tab places the current range beside the reference period. This lets you check whether the number of physical printers used, physical print scale, pages, file outputs, errors, cancellations and the count of involved computers or employees changed.

During comparison, pay attention to:

  • an increase in Physical Prints, especially when the reference period was quiet.
  • a change in Physical Printed Pages, because it reflects paper load better than job count alone.
  • growth in Prints to File, which may indicate documents being saved instead of printed physically.
  • a jump in Print Data Size, especially when it comes from one document or one printer.
  • more cancelled or failed prints, because this may point to a technical issue rather than a change in user behaviour.

If the comparison shows an unusual increase, start with the metric that moved most and then open printer, document and computer rankings. This order helps avoid the quick assumption that the whole team printed more when one device or one file caused the change.


Anomalies in print monitoring and large jobs

Anomalies mark situations where printing differs from the previous period or a single element has unusual scale. The mechanism does not assess document content; it works with counters, sizes, statuses and detailed data saved by the agent.

This view can show, among others:

  • Print volume increased significantly - when the number of print jobs is clearly higher than in the comparison period.
  • Large print data volume detected - when the data size for a printed document crosses the anomaly threshold.
  • information about a high PDF fallback share, if that rule is enabled in the anomaly mechanism.

Anomaly evidence may include current print jobs, baseline print jobs, print job increase, print data size, pages, document and printer. For a large data size, open the record details and check the document, file path, source, status and whether page count is known. For a period-level increase, compare computers and employees before moving to individual documents.


Record details in print job monitoring

After selecting a record, the application shows job details aggregated for one day and one computer. Repeated entries for the same document or the same path may be merged, so one detail row can show the activity sum and the latest known print context.

In the details table, check first:

  • print identification: document, printer, file path and item key.
  • type and result: Print Output Type, status, successful, cancelled and failed prints.
  • counters: physical prints, physical printed pages, prints to file, file output pages and print jobs.
  • size and reliability: print data size, confidence and page count known.
  • source context: print source, source type, provider, category and message.
  • event frame: first seen, last seen, active hours, user and client computer.

Print usage details cannot be narrowed by hour. The active-hour bitmask only tells whether something happened in a local hour, without assigning jobs, pages or data size to that hour, so treat the details as a daily print activity summary for the selected computer.


Data quality in print usage monitoring

The data quality section helps verify whether daily records have available details and whether those details match the summary. Print events can be collected from different system sources, so it is worth checking not only job count but also how completely printers, documents and file paths are broken down.

In the quality block, review:

  • Details Coverage - the percentage of entries where the print job list is available.
  • Records Without Details - days with print activity but no item breakdown.
  • Current Partial Data - entries from today that may still be waiting for aggregation to finish.
  • Historical Open Records - old print days left open instead of being finalised.
  • Invalid Details - detail payloads whose print structure cannot be parsed.
  • Missing Data Days - gaps in the selected monitoring range.

If you see a quality warning, do not start with the assumption that printing did not happen. First check whether the record is current, whether details are still being aggregated and whether the agent has Print Monitoring enabled. Only then decide whether the issue belongs to the event source, monitoring profile or backend export.


Print monitoring settings in the agent profile

The data visible in this view depends on the monitoring profile assigned to the computer. In the Printing section, editable options decide whether the agent collects print data and how it handles cases where standard system events do not provide a full picture.

For print monitoring, the key settings are:

  • Print Monitoring - the main switch for collecting print activity.
  • Print Scan Interval (seconds) - the scanning interval, available from 5 to 300 seconds.
  • PDF Print Fallback Monitoring - an additional method for detecting PDF events, useful when the normal source is not reliable enough.
  • PDF Print Fallback Window (seconds) - the PDF fallback correlation window, available from 10 to 600 seconds.
  • Print File Transfer Monitoring - an option related to printing to file; it works as part of file transfer monitoring and requires File Transfer Monitoring to be enabled.

If the table lacks physical prints, first check whether the profile has Print Monitoring enabled. If the issue concerns PDF documents or file outputs, verify PDF fallback and the print file transfer setting. A very short interval can make data appear faster, but the agent performs more frequent reads, so choose it according to computer count and the expected monitoring accuracy.