The Deny Count on the Organizations page provides an approximate view of denied activity across an environment. It is intended to help identify overall trends and should not be expected to match the Unified Audit results exactly.
Because the Organization Deny Count and the Unified Audit use different calculation methods, filtering, and time zones, differences between the two are expected.
Why the Organization Deny Count May Differ from the Unified Audit
Several factors can cause the Organization Deny Count to differ from the results shown in Unified Audit.
Time Zone Differences
The Organization Deny Count is calculated using UTC.
The Unified Audit displays results using the machine's local time.
Because the same date range may represent different periods depending on the time zone, events near the beginning or end of the selected range may appear in one result set but not the other.
Moved or Deleted Computers
The Organization Deny Count excludes results associated with computers that have been:
- Moved to another organization
- Deleted
The Unified Audit does not remove these historical events. As a result, the Unified Audit may continue to show activity from a computer that is no longer included in the organization's current deny count.
How the Organization Deny Count Is Calculated
The calculation varies depending on the type of denied activity.
Executes
For application execution denies, the Organization Deny Count:
- Searches for Any Deny
- Excludes events generated by explicit Deny policies
- Groups matching events by SHA-256
Multiple events involving the same SHA-256 are therefore represented as a single item in the deny count.
Ringfenced
For Ringfencing denies, the Organization Deny Count:
- Searches for the Ringfenced action
- Groups matching events by Full Path
Multiple Ringfencing events involving the same full path are grouped together and count as a single item.
Network
For Network denies, either from being Ringfenced or from a Network policy, the Organization Deny Count:
- Searches for the Ringfenced action and the Network action type
- Groups matching events by Destination IP Address
Multiple matching events involving the same destination IP address are grouped together and counted as a single item.
The Organization Deny Count Is an Approximation
The Organization Deny Count is designed to provide an approximate representation of denied activity and overall trends, rather than an exact audit total.
Use the Organization Deny Count to quickly identify changes and trends in file blocking. Use the Unified Audit when investigating individual events or reviewing detailed audit information.
Help Center