Skip to main content

Change Tracking

The Change Tracking page records configuration changes made to your Proxmox infrastructure over time. It answers the critical question: who changed what, and when?

Overview​

ProxCenter periodically snapshots the configuration of your VMs, containers, nodes, and storage. When a difference is detected between two snapshots, a change record is created with a diff view showing exactly what was modified.

This feature is particularly valuable in team environments where multiple administrators manage the same infrastructure, and for compliance requirements that mandate an audit trail of configuration changes.

Prerequisites​

  • Active inventory synchronization.
  • Permissions to read the resources being tracked.
  • Stable resource identifiers such as VMID, node name, storage ID and connection ID.

Change Tracking is most useful when ProxCenter is the primary operational interface. Changes made directly in Proxmox are still detected, but attribution may be limited to the Proxmox task user or the polling context.

What Gets Tracked​

ResourceTracked Changes
VMsCPU, memory, disk, network, boot order, cloud-init, options, tags
ContainersCPU, memory, rootfs, mount points, network, features
NodesNetwork interfaces, DNS, hosts file, kernel parameters
StorageStorage configuration, content types, enabled state
FirewallRules, aliases, IP sets, options at cluster, node, and VM level

Diff View​

Each change record includes a side-by-side or unified diff showing the previous and new values. Configuration keys that were added, removed, or modified are highlighted:

  • Green -- New configuration added
  • Red -- Configuration removed
  • Yellow -- Value changed (shows before and after)

Timeline​

Changes are displayed on a timeline, grouped by day. You can filter the timeline by:

  • Resource type -- Only VMs, only nodes, etc.
  • Connection -- Limit to a specific Proxmox cluster
  • Date range -- Focus on a specific time window
  • User -- Show changes attributed to a specific Proxmox user (when available from the task log)

Exporting the Timeline​

The filter row carries the page's actions as icons: Change Tracking Settings, whose tooltip states the current retention, Export CSV, Refresh and Purge all changes.

Export CSV exports what the filters select, every page of it, not the rows currently on screen. The file carries one row per change, with the columns Date, Resource type, Resource ID, Resource name, Action, User, Node, Connection, Fields changed and Details.

Two details that matter when the file is opened elsewhere: values are quoted to RFC 4180, because a configuration diff routinely carries commas, quotes and line breaks, and the file starts with a byte order mark so a spreadsheet reads its UTF-8 headers as UTF-8 rather than as mojibake.

Notifications​

You can configure alerts to be notified when specific types of changes occur. For example, get an email when a VM's network configuration changes, or when a firewall rule is modified.

warning

Change detection relies on periodic configuration snapshots. Changes made and reverted between two snapshot intervals may not be captured. The default snapshot interval is 5 minutes.

Review Workflow​

For operational reviews, filter by date range and resource type, open the diff, then correlate the change with Audit Logs and Events. This helps separate planned maintenance from unexpected configuration drift.

Enterprise Feature

Change Tracking is available in the Enterprise edition.

Permissions​

PermissionDescription
audit.viewView change history across all resources
vm.viewRequired to see VM and container change details