Skip to content

History and change tracking

Snapshots, diffs and attestation

Edit this page
On this page

An inventory that only tells you what is true now cannot answer the question people actually ask after an incident: what changed?

Snapshots

A snapshot freezes the whole inventory at a point in time — hosts, services, ports, certificates, findings.

One is taken daily, and you can take one by hand before a change window. The inventory.snapshot job runs hourly and asks whether today's snapshot exists, rather than computing the next 02:00 and sleeping until it: a restart at 01:59 silently skipped a day under the old scheme, and hourly idempotent checking is both simpler and more robust.

Diffs

Compare any two snapshots. The result reports, per entity, what was added, removed or changed.

This is the fastest way to answer "what changed since Friday" — and, more usefully, "what changed between the last good state and now", which is the same question phrased by somebody having a bad afternoon.

A diff covers:

EntityReported changes
HostsAppeared, disappeared, changed identity or OS
ServicesStarted, stopped, changed version
PortsOpened, closed, changed state
CertificatesAppeared, replaced, expired
VulnerabilitiesNewly matched, resolved

The change feed

Every host page carries its own change feed, so you can see one machine's history without picking snapshots at all. It is the right surface for "when did this box start running Redis".

PDF attestation

Any snapshot exports as a PDF report listing the inventory at that instant. It is intended for auditors who want evidence of state on a date, rather than a live dashboard they have to be given access to.

Activity density

The History page carries a 60-day strip showing snapshot frequency. It exists for one reason: a gap in it means the scheduler stopped running, and that is otherwise a very quiet failure — nothing errors, the inventory just stops being recorded.

If you look at one thing on that page after an upgrade or an outage, look at the strip.

Retention

Snapshots accumulate. There is no automatic pruning yet, which means disk grows in proportion to inventory size times days retained. For a large estate, plan for it: see Scaling.

Alerting on change

snapshot.diff_significant fires when a diff crosses a threshold you set, and host.added, host.removed and service.changed fire on the individual events. Route them under Settings → Integrations — see Notifications.

A useful pairing: host.added to a low-traffic channel for awareness, and snapshot.diff_significant to the channel people actually read.