How do you open web blocking monitoring?

Open the view from the application menu: Menu -> Monitoring -> Web - blocked. It shows events where the agent recognised a page or domain covered by a web rule and saved the blocking attempt together with browser context, URL, page title, window title, rule and matched value.

Use this view when you want to check whether users try to open blocked domains, whether one rule stops too many pages, whether blocking works correctly across browsers, or whether a new frequently blocked address appeared in the organisation. Web blocking monitoring shows the enforcement layer for website access, not general internet usage.

The layout includes the Analytics panel, the daily records table and the detail area. The panel leads through blocking counters, blocked domains, rules, failed actions, action success, top lists, charts, period comparisons, deviations, hourly presence and quality messages. A single table entry is a daily web blocking summary for one computer. After opening it, the application shows that day's items for the selected workstation and employee, grouped by domain, URL, rule, browser and match.


Daily table in blocked website monitoring

The table quickly shows where attempts to access content covered by web rules appeared. The first columns focus on the number of blocks and on which domain and rule had the largest share on that day.

In the basic table layout you will find:

  • Blocked - the number of successfully recorded blocks in the daily record.
  • Blocked domains - the number of different domains or entries recognised in the details.
  • Most Blocked Domain - the domain that appeared most often in the record.
  • Most Triggered Rule - the web rule responsible for the largest number of blocks.

After expanding columns, you can add Attempts, Failed Actions, Action Success, Most Used Action, Last Domain, Last Page Title, Last Browser and Last URL. Search also covers active hours, computer name, Windows user, domains, URLs, titles, actions, messages, rules, match type, matched value and details stored in ItemsJson.


Analytics panel in web blocking monitoring

The analytics panel summarises website blocking for the selected period. You can work with a day, week, month or custom range, and calculate values as Total or Daily Average. Daily Average is useful when you compare a short blocking series with a longer background of normal organisational work.

The most important panel metrics are:

  • Blocked - the number of stopped attempts to access web content.
  • Blocked domains - the number of domains recognised in the analysed range.
  • Blocking Rules - the number of rules involved in blocking.
  • Failed Actions - cases where the blocking action was not completed correctly.
  • Action Success - the percentage of attempted actions completed successfully.
  • Computers and Employees - the scope of workstations and users included in the analysis.

In practice, it is worth reading blocks together with failed actions. Many blocks with high action success may indicate a properly working policy. Many blocks with a rising number of failed actions require checking the browser, agent permissions or the action configuration itself.


Domain rankings in website blocking monitoring

Rankings show which elements trigger web blocking most often. Instead of reviewing every daily record separately, you can start with the domains, rules and browsers that create the largest event volume.

The panel includes, among others:

  • Top Blocked Domains - domains with the highest number of blocks.
  • Top Blocking Rules - web rules that most often stopped traffic.
  • Top Browsers - browsers visible in blocked events.
  • Top URLs - specific addresses repeated in the details.
  • Top window titles - window titles that help identify page context.
  • Top matched values - rule values that most often matched events.
  • top computers and employees linked to blocked attempts.

If one address is at the top of the domain ranking, open the details and check whether the block came from the domain, URL, page title or window title. With web rules, a small difference in the match target can decide whether the policy works precisely or stops too broad a set of pages.


Blocked domain trends in web monitoring

Trends show how blocking activity changed day by day. Separate charts cover Blocked, Blocked domains, Blocking Rules, Failed Actions, Action Success, Computers and Employees.

When reading trends, check:

  • whether the increase in blocks appeared after adding a new web rule,
  • whether the number of domains grows together with the number of blocks or whether one address dominates,
  • whether a drop in action success matches a specific browser,
  • whether the problem appears on one computer or spreads across several workstations,
  • whether blocked domains occur on the same days as policy violations or web transfers.

The Hourly Web Blocking Presence chart shows on what share of monitored days the agent noticed blocked web activity in a specific local hour. It is not the number of requests, the number of URLs or browsing time. A marked hour only says that at least one trace of web blocking appeared during that hour.


Comparisons in web block monitoring

The comparison area contrasts the selected range with its baseline and highlights how web blocking changed. In the Web - blocked view, it helps distinguish normal rule activity from a situation where more blocked domains, more rules or worse action success suddenly appear.

When analysing comparisons, pay attention to:

  • an increase in Blocked, because it shows the overall change in stopped attempts.
  • an increase in Blocked domains, especially when single addresses dominated earlier.
  • a change in Blocking Rules, because more rules may indicate new configuration or overly similar rules.
  • an increase in Failed Actions, which points to a problem with the agent's response.
  • a decrease in Action Success, even if the number of blocks has not grown sharply.

If the comparison shows a sudden change, start with domain and rule rankings, and only then analyse computers. In website blocking, a spike is often caused by a new match pattern, a domain category change or a page that started appearing in many sessions.


Anomalies in blocked web content monitoring

Anomalies point to events that exceed thresholds or clearly differ from the baseline period. In this view, the mechanism focuses on increased blocking, repeated attempts to open the same content, failed actions and new domains that quickly began generating blocks.

The panel may show, among others:

  • Blocked web activity increased significantly - when the current range clearly exceeds the reference period in blocked occurrences.
  • Repeated attempts to access blocked web content - when a computer or employee repeatedly hits a blocked domain.
  • Web blocking action failed - when the agent tried to perform a response, but some attempts ended with an error.
  • New domain is being blocked repeatedly - when a domain was not visible in the comparison period but reaches the attempt threshold in the current range.

In anomaly evidence, check current and baseline blocked count, blocked count increase, attempts, domain, rule, action, browser and failure share. This helps separate a user behaviour issue from a technical problem with executing the block.


Record details in blocked URL monitoring

After clicking an entry, the application shows web blocking details for one day and one computer. Items are grouped so you can move from a daily result to the specific domain, URL, rule and match that triggered the action.

In the details table you will find:

  • page context: Domain, Page Title, Window Title and URL.
  • browser context: Browser and active hours of event visibility.
  • rule logic: Rule, Rule ID, Match Type, Match Target and Matched Value.
  • response execution: Action, Action Message, Blocked, Attempts and Failed Actions.
  • event time: First Seen and Last Seen.

The default sort starts with the number of blocks, so the most important domains usually appear at the top. Hourly filtering does not split counters into individual hours, because the active hours mask stores only occurrence presence. Treat the details as a daily summary of blocked content, not as a full history of every HTTP request.


Data quality in web blocking monitoring

The data quality section indicates whether daily records have consistent details for domains, URLs, rules and actions. This matters because the number of blocks says little without knowing which page was stopped and which rule recognised it.

The quality panel may signal missing details with present counters, an invalid data structure, timestamps outside the day's boundaries, a mismatch between the summary and item list, the current day still being aggregated, or a closed record without web blocking details.

When the quality message refers to the current day, give the backend time to close aggregation. For historical dates, verify the agent state, ItemsJson presence and consistency between attempts, blocks, successful actions and failed actions in the detail rows. Only after this check is it worth evaluating the effectiveness of web rules.


Web blocking monitoring settings

The data visible in this view depends on editable settings in Monitoring Profiles. The most important switch is Web Blocking. Only after it is enabled can the agent enforce web rules and record website blocking events.

The second key element is Web Block Rules. Each rule can have a name, match value, match type, match target, action and rule enabled switch. In practice, it is worth giving rules clear names, because they later appear in the table, rankings and anomalies.

The same settings area also contains Browser Insight and Browser Insight Interval (seconds). These options help provide web context, such as addresses, titles and browsers, but they do not replace blocking rules. After changing rules, return to Web - blocked after the next monitoring day and check Top Blocked Domains, Top Blocking Rules, Failed Actions and Action Success.