How do you open remote and local work monitoring?

Open the view from the application menu: Menu -> Monitoring -> Sessions. In this manual we describe it as remote and local work monitoring, because the data in this panel helps assess computer activity whether the employee works from the office, home or another location. In the table and panel you can find Active Time, Idle Time, Foreground Time, Activity, Idle, Interactions, Keyboard Count, Mouse Clicks, the last process and the last window title.

Use this view when you want to understand the rhythm of a workday, separate real activity from a session left open, check the relation between activity and idle time or compare computer activity across a selected period. Remote and local work monitoring does not evaluate the content of work; it analyzes technical activity signals: time, interactions, applications and hourly presence.

The view layout combines the Analytics Panel, a list of daily records and a details area. The panel presents period metrics, application rankings, window titles, activity states, trends, comparisons, anomalies, hourly presence and quality messages. One row in the list corresponds to one monitored day on a specific computer. Selecting it opens the activity picture for that workstation and user, divided mainly by applications, windows, active time, idle time and interaction count.


Daily table in remote and local work monitoring

The daily table quickly shows whether a computer was used actively or only remained in an observed session. The important part is reading several columns together: a long observed time alone does not yet say how much of that period was active work.

In the basic table layout you see:

  • Active Time - the time in which the agent recorded active computer use.
  • Idle Time - periods without user activity according to the configured idle threshold.
  • Activity - the percentage share of active time in active and idle time.
  • Interactions - the combined number of keyboard actions and mouse clicks.

After expanding columns, you can check Foreground Time, Keyboard Count, Mouse Clicks, Last Process, Last Window Title, Computer Observed Time, User Session Observed Time, Idle and second-based values. Search covers date, computer, Windows user, Active Hours, last event type, process, window title and detail content.


Analytics panel in work activity monitoring

The analytics panel summarizes the selected date range and lets you switch between Total and Daily Average. Total shows the full activity volume for the period, while Daily Average helps compare shorter and longer ranges without confusing the result with the number of days.

The key panel metrics are Active Time, Idle Time, Foreground Time, Activity, Idle, Interactions, Keyboard Count, Mouse Clicks, Computers and Employees. Start with the relation between activity and idle time, then look at interactions, because different types of work generate very different numbers of clicks and keyboard actions.

In remote and local work monitoring, the panel helps answer two practical questions: whether the computer was actually used, and how that activity was distributed across applications, windows and employees. Record details then show which elements formed the result for a specific day.


Application rankings in remote and local work monitoring

Rankings show where active time was concentrated. They let you move from a general activity percentage to the specific applications, windows, computers and employees that shaped the period result most strongly.

The rankings panel includes, among others:

  • Top Applications - applications with the largest share of active time.
  • Session Window Titles - window titles linked to foreground activity.
  • Session Activity States - the time split between activity and idle state.
  • Top Computers and Least Active Computers - a quick comparison of workstations.
  • Top Employees and Least Active Employees - users ordered by active time.

If one application dominates the ranking, check the day details and window titles. In remote and local work, the process name alone is not always enough, because the same application can support many different tasks.


Activity trends in remote and local work monitoring

Trends show how activity changed from day to day. You can switch charts for Activity, Idle, Active Time, Idle Time, Foreground Time, Interactions, Average Computer Activity and Average Employee Activity.

When reading trends, check:

  • whether a drop in Activity is a one-day event or continues for several days,
  • whether growth in Idle Time appears together with fewer Interactions,
  • whether Foreground Time grows together with Active Time,
  • whether the change affects many computers or only one workstation,
  • whether Average Employee Activity moves similarly to Average Computer Activity.

The Hourly Session Presence chart indicates which local hours contain at least one activity record in the analyzed days. It should not be read as exact active time or idle time within that hour. A marked bar means that data was present in that interval.


Work time comparisons in remote and local monitoring

The comparisons tab shows the selected period and its reference range side by side. From that view you can see whether total active time changed, whether idle share increased, whether interactions moved and whether work distribution across computers and employees looks different.

In comparisons, pay attention to:

  • the change in Active Time, because it gives the simplest direction of difference between periods.
  • the difference in Idle Time, especially when it grows faster than active time.
  • the change in Activity and Idle, so you do not rely only on hour values.
  • movement in Interactions, which can support or weaken the conclusion from active time.
  • the number of computers and employees, to make sure you compare a similar data scale.

If the current period differs strongly from the baseline, start with trends, then move to application rankings and record details. This order helps separate a work-organization change from a single day with a session left open.


Idle anomalies in remote and local work monitoring

Anomalies point to situations where activity looks unusual against thresholds or the comparison period. In this view they mainly concern high idle share, increased idle time, low activity and new processes appearing in the data.

The panel may show, among others:

  • High idle session share detected - when the observed time contains a very large idle part.
  • Idle session time increased - when the current period is much higher than the baseline.
  • Low session activity detected - when activity is very low despite sufficient observation time.
  • New session process detected - when a process appears in the current period but not in the comparison period.

In anomaly evidence, review Idle Time, Active Time, Idle Share, Last Process, Current Idle Time, Baseline Idle Time, Idle Time Increase, Activity and Input Events. These data points help decide whether the issue comes from a session left open, a changed work rhythm or a normal difference between tasks.


Record details in daily activity monitoring

After clicking a record, the application shows activity elements for one day and one computer. Process rows are the most valuable user-facing details, while older data may show a work summary when process-level details are not available.

The details table contains fields such as Application, Window Title, Active Time, Idle Time, Foreground Time, Activity, Interactions, Keyboard Count, Mouse Clicks, Process, Idle and Active Time Share. Additional columns may show Computer Observed Time, User Session Observed Time, Event Type, Category, Computer, Windows user, First Seen, Last Seen and Active Hours.

Start by sorting by Active Time or Foreground Time. Then check the window title and Active Time Share, because this helps separate an application that was truly used from a process visible only for a short part of the day.


Data quality in remote and local work monitoring

The data quality section tells you whether activity details are available and whether they agree with the daily summary. This matters because the table shows aggregates, while interpreting remote and local work usually requires seeing applications, windows and time span.

The quality panel may indicate missing details despite existing data, invalid JSON structure, elements outside the day boundaries, mismatch between details and summary, ongoing aggregation of the current day or a closed record without activity details.

If the warning concerns today's record, wait until aggregation finishes. For older records, check agent operation, the sending queue, ItemsJson availability and whether active time, idle time, keyboard and click totals agree with detail items. Only then is it worth drawing conclusions from differences between remote and local work.


Remote and local work monitoring settings

The data visible in this view is affected by editable agent profile settings related to activity and signal collection frequency. The most important ones are located in the basic settings and in the monitoring section.

Pay attention to:

  • Activity Monitoring - enables collection of data used to create active time, idle time and interactions.
  • Monitoring Sampling Profile - lets you choose the general agent operating profile, for example more accurate or lighter.
  • Use Explicit Sampling Intervals - when enabled, allows manual configuration of selected readout intervals.
  • Activity Sample Interval (seconds) - defines how often the agent collects activity samples when custom intervals are used.
  • Idle Threshold (seconds) - decides after how long without a user signal activity starts being counted as idle.

After changing these settings, observe Active Time, Idle Time, Activity, Idle and Interactions in the panel. A threshold that is too short can increase idle time during reading or calls, while a threshold that is too long can hide real breaks. It is best to change one parameter at a time and compare results over the next few days.