How do you open USB usage monitoring?
Open the view from the application menu: Menu -> Monitoring -> USB. It is used to observe USB device usage on computers covered by the agent: connections, disconnections, repeated detections, recognised models, serial numbers, drive letters, volumes, formats and drive types.
Open this view when you want to check whether USB storage devices appeared on a workstation, whether one device was repeatedly reconnected, whether new devices appeared in the organisation, or whether USB activity is concentrated on selected computers. USB usage monitoring does not describe blocking decisions. It shows factual traces of device presence and connection state changes.
The layout is built around the Analytics panel, the daily list and the detail area. The panel brings together connection change counters, unique devices, connections, disconnections, rankings, trends, comparisons, anomalies, hourly presence and data quality. One list entry represents a daily USB activity record for a single computer. After opening an entry, the application shows the details for that day, workstation and employee, aggregated by recognised USB devices and their technical parameters.
Daily table in USB device monitoring
The daily table lets you quickly determine whether a computer had USB activity on a specific day and how intense the device state changes were. In the basic layout, the most important columns are counters that describe the scale of activity without opening every device detail immediately.
The default columns include:
- Unique USB Devices - the number of logically recognised devices in the record.
- USB connection changes - the sum of connections and disconnections detected during the day.
- Connected - the number of events where a device was observed as connected.
- Disconnected - the number of events related to losing or ending a connection.
After expanding the table, you can also add USB device count, last device, last drive, last volume and last serial number. Search covers the date, agent identifier, computer, Windows user, active hours, drive name, volume, device identifiers, serial numbers and detail content. This makes it possible to find a record from only part of a volume label or a known device serial number.
Analytics panel in USB presence monitoring
The analytics panel collects data from the selected time range. You can analyse a day, week, month or custom range, and read values as Total or Daily Average. Total shows all activity in the period, while daily average helps compare short and long ranges.
The main panel metrics are:
- USB connection changes - the total number of connections and disconnections.
- Unique USB Devices - the number of recognised devices after identity deduplication.
- Connected and Disconnected - separate counters for the two directions of state change.
- Computers and Employees - the workstation and user coverage visible in the analysis.
These metrics are best read together. A high number of connection changes with a small number of unique devices may mean that the same device was repeatedly reconnected. An increase in unique devices with a moderate event count suggests that many different drives appeared, rather than one unstable port or one problematic device.
Rankings in USB device and drive monitoring
Rankings show where USB activity is concentrated and which devices account for the highest number of connection changes. This is a useful starting point when the table shows many events but it is not yet clear whether the result comes from one drive, one computer or several people.
The ranking panel includes:
- Top USB Devices - devices ordered by the number of connection changes.
- USB Drive Types - the distribution of recognised drive types.
- USB Drive Formats - file systems or formats visible in device data.
- Top Computers - workstations with the highest number of USB events.
- Top Employees - users associated with the highest activity.
When analysing the device ranking, do not rely only on the model name. Similar USB drives may have the same commercial name, so in the details it is worth checking the serial number, volume, drive letter and technical identifiers. Drive type and format distributions help assess whether the data is dominated by typical removable storage or whether other device classes are appearing.
USB usage trends in computer monitoring
Trends show how USB activity changed across the days in the selected period. Separate series cover USB connection changes, unique devices, connections and disconnections. This helps you see whether an increase was a single spike or lasted for several days.
When reading trends, check:
- whether a spike in connection changes appears together with an increase in unique devices,
- whether connections and disconnections grow at a similar pace,
- whether activity appears after a monitoring profile change or after new workstations were added,
- whether several computers follow a similar event rhythm or one machine stands out,
- whether new device presence occurs on the same day as unusual file transfers.
The Hourly Presence chart answers how often, across monitored days, the agent noticed USB activity during a particular local hour. It is not an event count, a connection distribution or device usage duration. A marked hour only means that a USB activity trace was present during that hour.
Comparisons in USB activity monitoring
The comparison area shows current results next to baseline data. In the USB view, it lets you quickly see whether the number of connection changes increased, whether more unique devices appeared, and whether the activity involves more computers or employees.
When analysing comparisons, pay attention to:
- an increase in USB connection changes, because it shows the overall change in activity intensity.
- an increase in Unique USB Devices, especially when the previous period had a stable device count.
- the difference between Connected and Disconnected, to catch unusual series of state changes.
- the change in the number of computers, because the same event increase has a different meaning on one workstation and across a whole department.
- the change in the number of employees, when you want to assess whether USB activity spreads across more user accounts.
If the current period differs strongly from the baseline, start with the device ranking and then move to computers. Only the record details will show whether the increase is driven by a new device, a frequently reconnected drive or a few ordinary events spread across different workstations.
Anomalies in USB device usage monitoring
Anomalies point to situations that differ from the comparison period or meet rule thresholds. In this view, the mechanism focuses on increased connection changes and on devices that were not present in the previous period.
The panel may show, among others:
- USB connection changes increased - when the number of connections and disconnections for a computer or employee is clearly higher than before.
- New USB device detected - when a device appears in the current period but was absent from comparison data.
- evidence related to connection counts, disconnection counts, the previous change level and the device's last action.
For a new device, check the model, serial number, volume and drive letter. For an increase in connection changes, it is more important to establish whether the events concern one drive or several different devices. If the same storage device appears many times in a short period, it may mean normal reconnecting, a USB port problem or work with an unstable drive.
Record details in USB parameter monitoring
After clicking a record, the application shows USB devices collected for one day and one computer. Details are deduplicated into logical devices so that several traces of the same drive do not artificially create many separate rows.
In the details table, check:
- device identification: Model, Serial Number, Device, Device ID and PnP Device ID.
- drive information: Drive, Volume, Drive Type, Drive Format and volume serial number.
- event counters: USB connection changes, Connected and Disconnected.
- storage capacity: Total Size, Available Free Space and Free Space Percent.
- visibility time: First Seen, Last Seen and Active Hours.
Sorting by model is the default, but in practice it is often better to start with the number of connection changes or the last detection time. Hourly filtering is not available for this view's details, because the active hours mask stores activity presence and does not assign USB counters to individual hours. Treat the details as a daily device summary, not a minute-by-minute drive log.
Data quality in USB usage monitoring
The data-quality area helps confirm whether daily USB records include enough device details to move from panel numbers to specific drives. In the USB view this matters because connections and disconnections alone are not enough to identify which device was actually used.
The quality panel may indicate missing details despite present counters, an invalid data structure, items with timestamps outside the day range, partial aggregation for the current day, older records left open or missing days in the selected period.
If a warning concerns today's record, wait until aggregation finishes and check again later. For closed days, verify agent operation, ItemsJson availability and consistency between the device list and connection change counters. Only after that check should you compare devices across computers or draw conclusions about unusual USB usage.
USB usage monitoring settings
Data in the USB view depends on configuration in Monitoring Profiles. For this page, the main editable control is USB Monitoring, which decides whether the agent should collect information about USB device activity on the computer.
The settings also show technical options related to detection sources, such as USB Logical Disk Monitoring, USB PnP Disk Monitoring, USB Volume Change Monitoring, Periodic USB Presence Events and USB Presence Event Interval (seconds). These fields are marked as read-only, so in a typical profile configuration they are not edited by the user.
If expected data does not appear in the USB view, first check whether USB Monitoring is enabled in the profile. Then make sure the agent has downloaded the current configuration and wait for the next daily record. Only later compare the records with file transfer or USB blocking views, because those pages describe different layers of work with external drives.
