---
title: Inventory
description: The IPs and hosts your connections revealed, the source of each one and the assets that stopped showing up in collection.
updated: 2026-09-27
---

The **Inventário** (Inventory) lists every IP and every host your connections revealed, deduplicated, along with the sources where each one appears. The screen shows what the Cloudflare account exposes today and what is no longer exposed.

Currently, there is a single source: the DNS records of the Cloudflare zones, as the screen footer says (**Fontes hoje: registros DNS das zonas Cloudflare.**, Sources today: DNS records of the Cloudflare zones).

:::note
The inventory is built from the DNS collection, which runs in the daily scan: once a day per connection, at 02:00 Brasília time. Before the first collection, the screen is empty and shows an explanation.
:::

## Summary

| Tile | What it counts |
|---|---|
| **Hosts** | Domains and names. |
| **IPs** | Destination and resolved IPs, with how many of them are internal. |
| **Presentes** (Present) | Assets seen in the most recent collection. |
| **Não vistos mais** (No longer seen) | Assets that left the sources. |

## Filter

Use the **Buscar IP, host ou zona…** (Search IP, host or zone) box and the filters below. Each filter accepts more than one option.

| Filter | Options |
|---|---|
| **Tipo** (Type) | Hosts, IPs, IPs públicos (public IPs), IPs internos (internal IPs). |
| **Papel** (Role) | Domínio (Domain), Host publicado (Published host), IP de destino (Destination IP), Alvo de CNAME (CNAME target), IP resolvido (Resolved IP), Servidor de e-mail (Mail server), Servidor de nomes (Name server), Alvo de SRV (SRV target). |
| **Situação** (State) | Presentes (Present), Não vistos mais (No longer seen). |

## Columns

| Column | What it shows |
|---|---|
| **Ativo** (Asset) | The IP or host. Internal IPs (RFC 1918 private ranges) get the **interno** (internal) badge. |
| **Tipo** (Type) | Host or IP. |
| **Papéis** (Roles) | The roles the asset appears in, such as **IP de destino** or **Alvo de CNAME**. |
| **Fontes** (Sources) | How many sources it appears in, as **N fonte(s)** (N source(s)). |
| **Situação** (State) | **Presente** (Present) or **Não visto mais** (No longer seen). |
| **Visto pela 1ª vez** (First seen) | The first collection it appeared in. |
| **Última vez** (Last seen) | The most recent collection it appeared in. |

The **Ativo** and **Tipo** columns and both dates can be sorted.

:::tip
Review IPs with the **interno** badge published in DNS records. They are private network addresses visible in DNS.
:::

## When an asset becomes "No longer seen"

A collection without the asset does not always mean it is gone. The rule depends on the role:

| Case | When it becomes **Não visto mais** |
|---|---|
| Resolved IP | After 3 consecutive collections without it. |
| Other roles | On the first collection without it. |
| Zone removed from the connection | Immediately, for every source in that zone. |

## Asset details

Select a row to open the asset panel. The top shows **Visto pela primeira vez em … · última vez em …** (First seen on … · last seen on …). Below, sources are split into two sections: **Onde aparece (N)** (Where it appears) and **Não visto mais (N)** (No longer seen).

Each source shows:

- the asset's role in that source;
- **Proxiado** (Proxied) or **Direto** (Direct), and whether the origin is exposed;
- the record path, in the format name → TYPE → content;
- the zone, with a link, and the connection;
- the period it was seen, with **· sumiu em …** (gone on …) once it left, or **· ausente na última coleta** / **· ausente nas últimas N coletas** (missing in the last collection / in the last N collections) while it is still being counted;
- an **Abrir …** (Open …) button to go to where the data comes from.

To review a zone's records, refer to [Zone details](/en/advisor/cloudflare/detalhe-da-zona/).

---

> Guardnet Docs · https://docs.guardnet.com.br/en/advisor/postura/inventario/
> Documentation index: https://docs.guardnet.com.br/en/llms.txt
