Change
How to find out what changed on the network between two collections
Most outages follow a change, and the hard part is rarely the fix. It is establishing what moved and on which device, at a point where nobody is volunteering that they touched anything. NacTrack compares each device's configuration against its previous collection and records what was added, removed and modified, so the question stops being who changed something and becomes which of these changes could produce the symptom.
Before you start
What you need
- Module required: core.
- Permission required: use_troubleshooting.
- All collected platforms; the comparison is on configuration text
1. See every change

2. Read the severity

3. Narrow to what matters

4. Apply and read the result

The limits
What this view does not tell you
- This compares collections, not moments. Two changes made between the same pair of collections appear as one combined difference, and a change made and reverted before the next collection leaves no trace at all.
- A change appearing here is not proof of a fault, and its absence is not proof of innocence. Plenty of outages come from something outside the configuration entirely - a failed optic, a neighbour's change, an expired certificate.
- Severity is assigned from what kind of configuration changed, so it reflects blast radius rather than intent. A deliberate, approved change to a routing statement still reads as high.
