What used disk space recently if I did not save a scan?
If a drive filled up before you started keeping scan history, SizeTrend can use the existing Windows NTFS change journal to find recent creation and extension activity. This gives you leads to investigate immediately.
Open recent file activity
Start SizeTrend with administrator access and scan the affected local NTFS drive.
In the Overview pane, open the Compared to: selector and choose Recent file activity (Windows journal).
Read the time range above the results, then inspect the largest entries. Each row identifies creation or extension activity and the file's current allocated space.
Click a result to locate the file in the scanned tree. Use the owning application's controls if it is managed data.
SizeTrend selects this view automatically when no earlier compatible scan is available and it can read the journal. You can also select it when saved scans exist.
A large result is a lead, not a growth measurement
The Windows journal records events but does not supply the file's old size. An existing 20 GB file extended by a small amount can therefore appear with a current size of 20 GB. That does not mean it consumed 20 GB during the displayed period.
SizeTrend matches journal events to files still present in the current scan. It does not reconstruct deleted files, display every write, or identify which process caused a change. Known system-managed paths are excluded from these results.
Why does the available time range vary?
Windows removes older records as its journal fills. A busy drive may retain a shorter period than a quiet drive; the view is not a fixed last-day or last-week report. SizeTrend reads at most the latest 1 GB of journal records and reports when this limit reduces the available range.
SizeTrend reads the existing journal without enabling it or changing its size. See Microsoft's change journal documentation for the underlying Windows mechanism.
If the view is unavailable or empty
Administrator access required: restart SizeTrend with administrator access and run a fresh scan.
Not an NTFS drive: this feature is for local NTFS volumes. Use saved-scan comparison or date filters for other supported filesystems and locations.
Journal unavailable or disabled: the view cannot recover events Windows no longer retains. Save a baseline for the next incident.
No matching files: retained events may concern files that disappeared, excluded system paths, or files outside the scanned folder. An empty list does not prove that no space was used.
If files changed after scanning, use the main Refresh command to update the scan. Refreshing only the Overview does not update all file sizes.
Use two scans for actual growth
Save a scan now and compare it after the next loss of free space. A saved-scan comparison can measure changes between those points in time; the journal view helps you investigate when that earlier measurement does not exist.