Skip to main content
Migration Notice
We're migrating documentation from the old portal into this one. Some things may look a little different or out of place in the meantime — we know, and we're working to get it right. If something's unclear or doesn't look right, let us know.

Inventory - Snapshot Timeline

The Snapshot Timeline is the historical-capture panel on the Lifecycle Watch page. It shows point-in-time captures of your Kubernetes inventory: the pods, PVCs, and nodes that existed when each snapshot was taken. Use it to answer historical questions such as "what was running last Tuesday at 14:00?" and to compare any two captures without relying on live data.

The panel is collapsed by default and sits below the primary lifecycle security surface (Deleted, Ephemeral, Recreated). Click its header to expand it.

Where: Data Security Posture > K8 inventory · lifecycle security > Snapshot Timeline

Overview​

A snapshot is captured automatically after a K8 scan job completes. How often depends on the Snapshot Frequency setting (Every Scan, Hourly, or Daily). See K8 Inventory Snapshots. Each snapshot is a fixed record of inventory at scan time: the pod list (with status), the PVC list (with storage class and capacity), and the node count. Snapshots cover the whole fleet.

The timeline lists up to the 100 most recent snapshots, newest first, on a vertical rail. The newest snapshot carries a latest badge.

Snapshot rail​

Each row on the rail shows:

FieldDescription
TimestampDate and time the snapshot was captured, with a relative age such as 2h ago
Pod countNumber of pods captured
PVC countNumber of PVCs captured
Node countNumber of cluster nodes captured
DurationHow long the scan that produced the snapshot took, in milliseconds

Click a row to expand it. The detail loads on demand and shows two tables:

  • Pods — namespace, pod name, node, and status. Running pods show a green status; any other state shows amber.
  • PVCs — namespace, PVC name, storage class, and capacity.

Click the row again, or press Esc, to collapse it.

Compare two snapshots​

To see what changed between two snapshots:

  1. Click the pin button on a snapshot row. It becomes pin A.
  2. Click the pin button on a second row. It becomes pin B.
  3. The Snapshot diff drawer opens from the bottom of the screen and shows the difference.

The drawer shows four columns:

  • Added pods — pods in the later snapshot but not the earlier one.
  • Removed pods — pods in the earlier snapshot but gone from the later one (struck through).
  • Added PVCs — PVCs that appeared between the two captures.
  • Removed PVCs — PVCs that disappeared (struck through).

Each entry shows namespace/name plus the node (pods) or capacity (PVCs). In the drawer header, clear pins resets both pins. The close button (✕) or Esc closes the drawer and keeps the pins. For more detail, see Snapshot Diff.

Workflows​

Find what was running at a specific time​

  1. Expand the Snapshot Timeline panel.
  2. Scroll the rail to the snapshot whose timestamp is closest to the time of interest.
  3. Click the row to expand it and review the pod and PVC tables.

See what changed overnight​

  1. Pin the snapshot from the start of the period (pin A).
  2. Pin the snapshot from the end of the period (pin B).
  3. Read the diff drawer. Added pods and Added PVCs are new arrivals. Removed pods and Removed PVCs are resources that went away.

Determine when a pod first appeared​

  1. Expand the oldest available snapshot and check whether the pod is listed.
  2. If it is not listed, work forward through newer snapshots until you find the first one that includes it. That snapshot's timestamp is when the scanner first observed the pod.

Tips​

  • Snapshots reflect only what the scanner observed at scan time. A pod or PVC created and destroyed entirely between two scans does not appear in either snapshot. To catch short-lived churn, use the Deleted, Ephemeral, and Recreated sections of Lifecycle Watch or the Pod Lifecycle Search panel, which draw on lifecycle data rather than discrete captures.
  • Expanding a snapshot loads its detail on demand, so a snapshot with many pods can take a moment to render the first time you open it.
  • No snapshots yet means no snapshot has been captured, because no K8 scan has completed. Run a K8 scan from the Jobs page, then refresh.
  • Change granularity is bounded by scan cadence and snapshot frequency. Anything that happens and reverses between two consecutive snapshots is invisible to the timeline.