Open recent file activity

  1. Start SizeTrend with administrator access and scan the affected local NTFS drive.
  2. In the Overview pane, open the Compared to: selector and choose Recent file activity (Windows journal).
  3. Read the time range above the results, then inspect the largest entries. Each row identifies creation or extension activity and the file's current allocated space.
  4. Click a result to locate the file in the scanned tree. Use the owning application's controls if it is managed data.

SizeTrend selects this view automatically when no earlier compatible scan is available and it can read the journal. You can also select it when saved scans exist.

A large result is a lead, not a growth measurement

The Windows journal records events but does not supply the file's old size. An existing 20 GB file extended by a small amount can therefore appear with a current size of 20 GB. That does not mean it consumed 20 GB during the displayed period.

SizeTrend matches journal events to files still present in the current scan. It does not reconstruct deleted files, display every write, or identify which process caused a change. Known system-managed paths are excluded from these results.

Why does the available time range vary?

Windows removes older records as its journal fills. A busy drive may retain a shorter period than a quiet drive; the view is not a fixed last-day or last-week report. SizeTrend reads at most the latest 1 GB of journal records and reports when this limit reduces the available range.

SizeTrend reads the existing journal without enabling it or changing its size. See Microsoft's change journal documentation for the underlying Windows mechanism.

If the view is unavailable or empty

  • Administrator access required: restart SizeTrend with administrator access and run a fresh scan.
  • Not an NTFS drive: this feature is for local NTFS volumes. Use saved-scan comparison or date filters for other supported filesystems and locations.
  • Journal unavailable or disabled: the view cannot recover events Windows no longer retains. Save a baseline for the next incident.
  • No matching files: retained events may concern files that disappeared, excluded system paths, or files outside the scanned folder. An empty list does not prove that no space was used.

If files changed after scanning, use the main Refresh command to update the scan. Refreshing only the Overview does not update all file sizes.

Find recent activity first, then measure the next change.

Use SizeTrend 3.2 or later for the features described in this guide.

Download SizeTrend