History and change tracking
Snapshots, diffs and attestation
Edit this pageAn inventory that only tells you what is true now cannot answer the question people actually ask after an incident: what changed?
Snapshots
A snapshot freezes the whole inventory at a point in time — hosts, services, ports, certificates, findings.
One is taken daily, and you can take one by hand before a change window.
The inventory.snapshot job runs hourly and asks whether today's snapshot
exists, rather than computing the next 02:00 and sleeping until it: a restart
at 01:59 silently skipped a day under the old scheme, and hourly idempotent
checking is both simpler and more robust.
Diffs
Compare any two snapshots. The result reports, per entity, what was added, removed or changed.
This is the fastest way to answer "what changed since Friday" — and, more usefully, "what changed between the last good state and now", which is the same question phrased by somebody having a bad afternoon.
A diff covers:
| Entity | Reported changes |
|---|---|
| Hosts | Appeared, disappeared, changed identity or OS |
| Services | Started, stopped, changed version |
| Ports | Opened, closed, changed state |
| Certificates | Appeared, replaced, expired |
| Vulnerabilities | Newly matched, resolved |
The change feed
Every host page carries its own change feed, so you can see one machine's history without picking snapshots at all. It is the right surface for "when did this box start running Redis".
PDF attestation
Any snapshot exports as a PDF report listing the inventory at that instant. It is intended for auditors who want evidence of state on a date, rather than a live dashboard they have to be given access to.
Activity density
The History page carries a 60-day strip showing snapshot frequency. It exists for one reason: a gap in it means the scheduler stopped running, and that is otherwise a very quiet failure — nothing errors, the inventory just stops being recorded.
If you look at one thing on that page after an upgrade or an outage, look at the strip.
Retention
Snapshots accumulate. There is no automatic pruning yet, which means disk grows in proportion to inventory size times days retained. For a large estate, plan for it: see Scaling.
Alerting on change
snapshot.diff_significant fires when a diff crosses a threshold you set,
and host.added, host.removed and service.changed fire on the individual
events. Route them under Settings → Integrations — see
Notifications.
A useful pairing: host.added to a low-traffic channel for awareness, and
snapshot.diff_significant to the channel people actually read.