How to open software removal monitoring?

You can open this view from the application menu: Menu -> Monitoring -> Software Removals. It is used to review operations where the agent tried to remove or clean software according to policy rules. Unlike the Software Changes view, this screen focuses on the result: whether removal started, whether it succeeded, whether additional steps were needed, and whether residuals remained afterwards.

Use this view after enabling automatic software uninstallation, after adding new removal rules, or when you want to check whether an unauthorized program keeps coming back after repeated installs. Software removal monitoring also helps separate successfully removed applications from cases where the command, permissions or cleanup logic need correction.

The view contains an analytics panel and a records table. The panel shows metrics, rankings, trends, comparisons, anomalies and data quality information. Each table row represents one monitoring day for one computer. Selecting a row opens operation details for that day, workstation and related employee, broken down by program, rule, status, step type, message and technical data.


Daily records in removed software monitoring

The table shows daily summaries of removal operations saved by agents. The default columns are chosen so you can quickly see whether real removals appeared on a given day and whether the agent detected residuals that need attention.

The key table columns are:

  • Software Count - the number of software items covered by removal operations in the record.
  • Removed - the number of items removed or cleaned.
  • Residuals - the number of cases where traces requiring review were detected after the operation.
  • Most Removed Software - the program that appeared most often in the record.

After expanding columns, you can also analyze Last Rule, Last Type, Last Software, Last Display Version, Last Publisher, Last Rule Action, Last Message, Last Registry Key, Last User SID and Last Rule ID. These diagnostic fields help explain not only what was removed, but also which mechanism made the decision.

The search can use date, agent, computer, Windows user, software name, rule, message, removal type, publisher, rule action, registry key, user SID, rule ID and detail text. That lets you locate a specific operation even when you only remember part of the message or rule name.


Analytics panel in removal success monitoring

The analytics panel summarizes software removals for the selected date range. You can review a day, week, month or custom period, and count data as Total or Daily Average. In this view, daily average is especially helpful when you compare a short policy test with a longer production period.

The most important metrics are:

  • Software Count - how many unique software items appeared in removal operations.
  • Removed - how many items were removed or cleaned.
  • Residuals - how many times the agent detected leftover files, registry entries or other elements after removal.
  • Computers - how many computers had these operations.
  • Employees - how many users were linked to the records, if the system could identify them.

The relationship between Removed and Residuals matters most. A high removal count with few residuals usually means the configuration works well. When residuals rise together with removals, review cleanup rules, uninstall commands and agent permissions on computers.


Rankings in removal rule monitoring

Rankings show which programs, rules and computers generate the largest part of removal operations. In software removal monitoring, a high position does not automatically mean a problem. It can simply show a rule that works according to policy and regularly removes an unauthorized program. The risk starts when residuals or unsuccessful statuses appear together with a high ranking.

The panel includes:

  • Top Removed Software - programs with the highest number of removed or cleaned items.
  • Top Removal Rules - rules that most often led to removal.
  • Removal Statuses - distribution of statuses returned by operations.
  • Top Computers - computers where removals occurred most often.
  • Top Employees - users connected with the largest number of such events.

Read rankings in pairs. If the same program and rule are high, check status details. If a high result appears across many computers, the issue may be policy-related. If it concerns one computer, the program may be reinstalled locally or cleanup may be failing on that workstation.


Trends and hourly presence in removal monitoring

Trends show how values changed across consecutive days. You can observe Software Count, Removed, Residuals, Computers and Employees separately. This split helps you see whether the number of operations is growing, or whether their reach in the organization is expanding.

When reading trends, check:

  • whether removals increased after changing rules or a monitoring profile,
  • whether residual growth concerns one program or many applications,
  • whether operations repeat cyclically, which may mean the removed program is being installed again,
  • whether the number of computers grows faster than removals, because that means the topic is spreading across the environment.

The Hourly Software Removal Presence chart presents the share of monitored days with at least one removal event recorded in a given local hour. It is not the number of removals or the duration of an operation. A marked hour only tells you that the agent recorded the presence of such an event.


Comparisons in cleanup operation monitoring

Comparisons help assess whether the current period differs from earlier environment behavior. In this view it is especially important to separate an increase in successful removals from an increase in post-removal problems, because both can rise at the same time while meaning different things.

When reading comparisons, pay attention to:

  • an increase in Removed, which can indicate successful rollout of a new rule or more programs requiring removal,
  • an increase in Residuals, because it points to cleanup that needs refinement,
  • an increase in Software Count, which shows removal covers more different items,
  • an increase in Computers, which means actions are not limited to one workstation,
  • an increase in Employees, which may show the issue is tied to user behavior or permissions across several profiles.

If the comparison shows a residual spike, do not start with the number alone. Open software and rule rankings, then record details. Only status, step type and message usually reveal whether the problem is the uninstall command, process termination, folder cleanup or post-operation verification.


Anomalies in removed program monitoring

Anomalies highlight events that deserve attention sooner than ordinary table records. In this view, the system looks for both changes in removal volume and operation reliability problems. This helps you see not only that a program was removed, but also whether removal behavior became unusual.

The anomaly mechanism focuses especially on:

  • Software removal activity increased significantly - when the number of removal events is much higher than in the comparison period.
  • Software was removed repeatedly - when the same program appears in removals repeatedly.
  • Software removal residuals were detected - when files, registry entries or other traces remained after an operation.
  • Software removal actions failed repeatedly - when operations did not report a successful status.

For anomalies related to residuals or failures, go straight to details. Anomaly evidence may show software, rule, computer, user, removed count and residual count, but the operation message usually explains which step needs work.


Record details in removed software monitoring

After clicking a record, the application shows removal items saved for one day and one computer. Details let you check the specific program, publisher, version, rule and operation status. This is the most important place when you want to confirm whether removal really completed successfully.

In the details table, check especially:

  • Software, Publisher and Version, which identify the program.
  • Rule, Rule Action and Rule ID, which show which policy started the operation.
  • Status, Type and Step Type, which describe removal progress.
  • Removed and Residuals, the key result counters for a specific item.
  • Message, Registry Key, Windows User, User SID and Operation ID, which support technical diagnosis.
  • First Seen, Last Seen, Active Hours, Day Start and Day End, which provide time context for the record.

Hourly filtering does not split removal counters into individual hours. The activity mask stores event presence, so details should be treated as a daily summary of operations and steps, not as a minute-by-minute installer or uninstaller log.


Data quality in software removal monitoring

Quality and freshness sections show whether the numbers visible in the panel have complete details behind them. For software removals this matters because a counter can say that an operation occurred, but without details you may not know whether it succeeded, which step stopped, or whether residuals remained.

In the panel you may see:

  • Details Coverage - shows what part of records has a ready removal operation description.
  • Records Without Details - records with removal activity but without the operation list.
  • Live Partial - current-day records that may still be aggregating.
  • Historical Open Records - older records that were not closed.
  • Invalid Details - entries whose removal details cannot be read as a valid structure.
  • Missing Data Days - completed days in the chosen range where no software removal monitoring data arrived.

If warnings appear only for the current day, they may simply result from ongoing aggregation. If they concern closed days, check the agent state, computer availability, and whether removal operations generate data the application cannot parse correctly.


Software removal monitoring settings

Software removal is controlled by Monitoring Profiles in the software section. Profile settings are sent to the agent with configuration and start working after the computer receives them. If a computer has no separate assignment, it uses the default profile.

The most important options for this view are:

  • Software Scan - gives the agent a reference point for recognizing installed programs.
  • Software Change Monitoring - records events that can be connected with later removal.
  • Software Installation Blocking - allows installations to be stopped according to policy rules.
  • Automatic Software Uninstallation - allows rules to start program removal.
  • Aggressive Silent Software Removal - enables additional cleanup actions when ordinary uninstall does not remove everything.
  • Software Installation Rules - where removal behavior and reactions to detected programs are defined; in a single rule, Name, Match Type, Value, Action, and for automatic removal also Silent Uninstall Command and Silent Uninstall Arguments, are important.

A rule with an automatic uninstall action is not enough if Automatic Software Uninstallation remains disabled. In that configuration the agent can recognize the case, but will not proceed to actual removal. After changing a profile, check this view after the next monitoring day: Removed shows rule effectiveness, while Residuals tells you whether cleanup needs more work.