How to open software change monitoring?
You can open this view from the application menu: Menu -> Monitoring -> Software Changes. Its purpose is to show what happened to software on monitored computers: which applications were installed, updated, uninstalled, detected as installation attempts or stopped by policy.
This screen is useful when you want to check whether a new program appeared in the environment, whether updates are behaving as expected, whether users are trying to install unauthorized tools, and whether automatic software removal was actually started. Software change monitoring connects security control with everyday administrative order.
The view consists of an analytics panel and a daily records table. The panel lets you switch date ranges, counting mode, rankings, trends, comparisons and anomalies. The table below the panel shows records where one record means one monitoring day for one computer. After selecting a record, the application opens the details for that day, computer and employee, broken down by software, publisher, change type, versions, rule and blocking information.
Record list in software program monitoring
The table is a daily register of changes saved by agents. By default, it shows columns that help you quickly distinguish a normal update day from a day with unusual installations or policy blocks.
The most important visible columns are:
- Changed Software - the number of unique software items detected in the record.
- Updated - the number of programs for which the agent recorded a version change.
- Blocked Installs - the number of detected installation attempts stopped by rules.
- Most Changed Software - the program that appeared most often in the record.
Column settings can reveal additional context, including Installed, Uninstalled, Event Count, Install Attempts, Auto Uninstall Attempts, Auto Uninstall Started, Policy Blocked, Most Common Change Type, Last Publisher, Last Registry Key, Last Rule Action and Auto Uninstall Message.
Search covers the date, computer, agent, Windows user, software name, publisher, change type, version, registry key, rule name, rule action and text stored in details. This makes it possible to find a specific change even when you only know part of the application name or the previous version.
Analytics panel for update and install monitoring
The analytics panel summarizes data from the selected range. You can switch the analysis between a day, week, month and custom range, then choose the counting method: Total or Daily Average. The first mode shows the total volume of changes, while the second helps compare periods of different lengths.
The available indicators are:
- Unique Software - the number of different programs visible in changes.
- Updated - programs whose version changed during the analyzed period.
- Installed - new software items detected on computers.
- Uninstalled - programs removed from monitored workstations.
- Blocked Installs - installation attempts or installer launches stopped by policy.
- Computers and Employees - the reach of changes in the environment.
In practice, it is worth reading these values together. A rise in updates may be normal after a patch deployment day, but a simultaneous increase in installs, uninstalls and blocked attempts can point to manual user activity or a change in software policies.
Rankings in software change monitoring
Rankings show where events accumulate. In the Software Changes view they are especially useful because the event count alone does not tell you whether the pattern involves one popular application, many publishers, a specific computer or a broader organizational trend.
The available summaries include:
- Top Changed Software - programs with the largest number of change events.
- Change Types - the distribution of installs, updates, uninstalls and other detected types.
- Publishers - software vendors appearing in records.
- Top Computers - workstations with the largest number of changes.
- Top Employees - users associated with the highest event volume.
A good way to use rankings is to move from the general picture to the detail. First check which software or change type dominates, then see whether it belongs to one publisher, and finally open the computer or employee that appears high in the summary.
Trends and hours in software change monitoring
Trends show how indicators changed across consecutive days. You can observe Unique Software, Updated, Installed, Uninstalled, Blocked Installs, Computers and Employees separately. This split helps distinguish ordinary update traffic from a sudden wave of new installations or software removal.
When analyzing trends, pay attention to:
- days when installs increase without a similar rise in updates,
- uninstalls appearing on many computers at the same time,
- blocked installs repeating after a monitoring profile change,
- a large increase in the number of computers, because it indicates that the change is not an isolated case.
The Hourly Software Change Presence chart has a different meaning than a standard counter. A marked hour means that at least one software change occurred during that local hour on a monitored day. It is not the number of changes, the number of installs or the duration of an installation process.
Period comparisons in program installation monitoring
Comparisons help you check whether the currently selected range behaves differently from the earlier reference period. In software change monitoring this is especially useful after introducing new rules, updating company packages or changing profiles assigned to computers.
It is best to interpret comparisons through the type of change:
- an increase in Updated often means planned patching, but it is worth confirming it with the software ranking,
- an increase in Installed can indicate new tools deployed by IT or installations performed by users,
- an increase in Uninstalled helps detect software removal across multiple workstations,
- an increase in Blocked Installs may show that rules started working or that users keep repeating forbidden actions,
- a rise in Computers and Employees separates a local incident from a change spreading across a larger part of the organization.
If the comparison shows a major jump, it is best to move directly to rankings and record details. There you can see the program name, publisher, previous and current version, and the rule that may have stopped the installation.
Anomalies in software program monitoring
Anomalies surface situations that do not need to be searched for manually in the table. The system analyzes both the change of the whole period against the comparison period and single daily records where repeated install attempts or automatic uninstall activity appeared.
This view can show, among others:
- Software change activity increased significantly - when the number of events is clearly higher than before.
- Repeated blocked software installation attempts - when policy repeatedly stopped an installation or installer launch.
- Automatic software uninstall activity detected - when the agent started the removal mechanism according to a rule.
- New software is changing frequently - when a program did not exist in the previous period but now generates many events.
- High software install attempt volume - when one day and computer contain an unusually large number of installation attempts.
Each anomaly includes evidence such as event count, install attempts, software name, publisher, rule, computer and user. Start with anomalies related to policy and automatic uninstall, because a system decision may already have affected the computer.
Record details in software version monitoring
After clicking a record, you will see the list of software items saved for one day and one computer. Details let you move from a daily counter to a specific program, its publisher, previous version, current version and rule data, if the event was connected with policy.
Details can include, among others:
- Software, Publisher and Change Type, which identify the event.
- Previous Version and Current Version, which help confirm an update or installation change.
- Blocked Installs, Install Attempts, Installed, Uninstalled and Updated, meaning counters for the specific program.
- Rule, Rule ID, Rule Action, Blocked By Policy and Auto Uninstall Message, meaning the policy decision context.
- Registry Key, First Seen, Last Seen, Active Hours, Source, Source Type, Category and Item Key, meaning technical data for diagnostics.
Hourly filtering for software change details does not split counters into individual hours. The activity mask stores information about event presence during an hour, so details should be treated as a daily list of items, not as a full installer timeline.
Data quality in software change monitoring
Quality indicators help you assess whether panel results have complete detail data behind them. This matters because a daily record may contain install or update counts, while the list of specific programs may still be aggregated or may have a data structure problem.
In quality and freshness sections you may see, among others:
- Details Coverage - the percentage of records for which change details are available.
- Records Without Details - days where counters indicate activity, but the item list is not available.
- Live Partial - current-day records that may still be filling in.
- Historical Open Records - older days that were not closed correctly.
- Invalid Details - records where software change details have an invalid structure.
- Missing Data Days - elapsed days in the selected range without software change monitoring data.
If the warning concerns the current day, it is usually worth waiting for aggregation to finish. If it appears for closed historical records, check the agent, data synchronization and whether the computer was available during the analyzed period.
Software change monitoring settings
The configuration of this view comes from Monitoring Profiles, in the software-related section. The profile defines whether the agent should scan software, save changes, react to installation attempts and apply automatic uninstall rules. New settings start working on computers after the agent receives the current configuration; a computer without a separate assignment uses the default profile.
The most important options for the Software Changes view are:
- Software Scan - allows the agent to build the installed software picture that later change detection relies on.
- Software Change Monitoring - enables saving installs, updates, uninstalls and other changes visible in this report.
- User Software Change Monitoring - covers changes made in the user context.
- Service Software Change Monitoring - covers changes detected by the agent service.
- Software Installation Blocking - lets the agent detect and stop installations according to rules.
- Automatic Software Uninstallation - allows rules to start software removal when policy conditions are met.
- Aggressive Silent Software Removal - strengthens removal with additional cleanup actions when ordinary silent uninstall is not enough.
- Software Installation Rules - the rule list where you set Name, Match Type, Value, Action, Silent Uninstall Command and Silent Uninstall Arguments.
Rules using the Auto Uninstall action will only detect software until Automatic Software Uninstallation is enabled. After changing a profile, it is useful to return to this view after the next monitoring cycle and check whether blocked install counts, auto-uninstall activity and software rankings match what the policy was supposed to enforce.
