On this page
Short answer
In File Timeline, choose the folders you want to follow and select Start observing. Make a small change to a sample file, then open the notification-area icon near the Windows clock to see the activity.
Before you start
- File Timeline from Microsoft Store and Windows 11 24H2 or later on an x64 PC.
- An accessible folder on a local NTFS drive and a harmless sample file. To check the file system, open This PC in File Explorer, right-click the drive, and choose Properties.
- Choose a folderObservation starts now.
- Rename a samplenotes.txt to trip-notes.txt
- Read the eventEarlier name and observed change.
Start here
Choose a small folder
Open File Timeline. Review the suggested Downloads and Desktop folders. Use Add folder to choose another supported location and uncheck any suggested folder you do not want to observe.
Start and review the scope
Select Start observing. Setup starts with subfolders excluded. If you need nested folders too, open Preferences and turn on Include subfolders for that location before making your sample change.
Make a sample change
In File Explorer, create or rename a harmless file inside the selected folder. Open File Timeline from its icon near the Windows clock and look for the activity.
Inspect the event
Select the activity and review Details. Open or Show in folder uses the file's verified current location when one is available.
Check your result
- The selected folder is available and observation is running.
- Your sample activity appears with a name and observed location you recognize.
- Use Back to live if you are viewing older activity and want the newest events.
If no activity appears
Check Preferences to confirm the folder and Include subfolders setting. Select Resume if observation is paused. A file in an excluded folder is outside the observation scope.
Review unavailable-folder notices and Observation interruptions. An empty timeline does not prove that no files changed, and setup does not reconstruct activity from before observation began.
Pause and retained history
Pause stops observation. Closing the panel only hides it; Exit File Timeline ends the application. Changes made while observation is stopped are not a complete recorded history.
Preferences includes Keep activity for. The default is 30 days, with choices from four hours to 90 days. Clear activity history removes the records, not your observed files.
What the timeline records
File Timeline records names, paths and evidence-backed activity. It does not copy file contents, restore deleted documents, or identify the person or program responsible for every change.
Links, unavailable locations and partially available cloud metadata can limit observation. Do not interpret a gap as a verified absence of changes.
Choose a monitor for the question you need to answer
For a file that exists now, start with File Explorer search. File Timeline is an option when you want to follow selected local NTFS folders from now on and later search retained names and paths. It cannot reconstruct activity from before observation or restore file contents.
FolderChangesView lists detected changes in a selected folder or drive and also supports network shares when you have read permission. Consider it when that monitoring scope is the requirement. File Timeline's supported scope remains local NTFS folders.
For troubleshooting which process performed a file operation, consider Microsoft Process Monitor. It records file-system activity with process details and filters. That diagnostic task is different from finding an earlier file name; choose a backup when you need the document's contents back.