Skip to content

Glossary

Glossary

Plain-language definitions of the FSEvents terms used by the parser and across the guides.

AppleDouble (._ files)
Companion ._name files macOS writes on FAT, exFAT and network volumes to store extended attributes and resource forks.
Data volume (/System/Volumes/Data)
The writable APFS volume holding user data since macOS 10.15; its .fseventsd folder carries most FSEvents evidence.
DLS page (1SLD, 2SLD, 3SLD)
The block structure inside decompressed FSEvents logs: a 12-byte header with a 1SLD, 2SLD or 3SLD magic, then packed records.
Event coalescing (FSEvents)
fseventsd merges several changes to the same path into one record, so one row can say Created, Modified and Removed.
FSEvents event ID
The 64-bit, ever-increasing counter stored with each FSEvents record; it orders changes but is not a timestamp.
FSEvents flags
The 32-bit bit set in each FSEvents record saying what changed (created, removed, renamed…) and the item type.
fseventsd-uuid
The file in .fseventsd holding the UUID of a volume's event stream; a new UUID means a new FSEvents history.
fseventsd
The macOS daemon that records file system changes and keeps them in a hidden .fseventsd folder on each volume.
LaunchAgent / LaunchDaemon
Property lists that tell launchd to start a program automatically, per user or system-wide; a classic macOS persistence place.
no_log (.fseventsd)
An empty marker file in .fseventsd that tells fseventsd not to record changes on that volume.
Node ID (FSEvents)
The file system object ID stored in 2SLD and 3SLD FSEvents records; it follows a file across renames and moves.
Quarantine attribute (com.apple.quarantine)
The extended attribute macOS adds to downloaded files so Gatekeeper checks them on first open; removing it skips that check.
TCC database (TCC.db)
The SQLite databases where macOS records privacy permissions such as Full Disk Access, camera or screen recording.