Change Journal

From Wikipedia, the free encyclopedia

Change Journal is a recording function of the changes on NTFS volumes.

When Windows 2000 was released, Microsoft created NTFS version 5.0, which included several new features and improvements over older versions of the file system. One of these was a new system management feature that is very useful for certain types of applications. Under Windows 2000, NTFS 5.0 partitions can be set to keep track of changes to files and directories on the volume, providing a record of what was done to the various objects and when. When enabled, the system records all changes made to the volume in the Change Journal, which is the name also used to describe the feature itself.

Change Journals work in a fairly simple manner. One journal is maintained for each NTFS volume, and it begins as an empty file. Whenever a change is made to the volume, a record is added to the file. Each record is identified by a 64-bit Update Sequence Number or USN. (For this reason Change Journals are sometimes called USN Journals.) Each record in the Change Journal contains the USN, the name of the file, and information about what the change was.

The Change Journal describes the changes that took place, but does not include all the data or details associated with the change, for this reason the Change Journal cannot be used to undo operations on files within NTFS.

[edit] External Links