Glossary
Glossary
Plain-language definitions of the FSEvents terms used by the parser and across the guides.
- AppleDouble (._ files)
- Companion ._name files macOS writes on FAT, exFAT and network volumes to store extended attributes and resource forks.
- Data volume (/System/Volumes/Data)
- The writable APFS volume holding user data since macOS 10.15; its .fseventsd folder carries most FSEvents evidence.
- DLS page (1SLD, 2SLD, 3SLD)
- The block structure inside decompressed FSEvents logs: a 12-byte header with a 1SLD, 2SLD or 3SLD magic, then packed records.
- Event coalescing (FSEvents)
- fseventsd merges several changes to the same path into one record, so one row can say Created, Modified and Removed.
- FSEvents event ID
- The 64-bit, ever-increasing counter stored with each FSEvents record; it orders changes but is not a timestamp.
- FSEvents flags
- The 32-bit bit set in each FSEvents record saying what changed (created, removed, renamed…) and the item type.
- fseventsd-uuid
- The file in .fseventsd holding the UUID of a volume's event stream; a new UUID means a new FSEvents history.
- fseventsd
- The macOS daemon that records file system changes and keeps them in a hidden .fseventsd folder on each volume.
- LaunchAgent / LaunchDaemon
- Property lists that tell launchd to start a program automatically, per user or system-wide; a classic macOS persistence place.
- no_log (.fseventsd)
- An empty marker file in .fseventsd that tells fseventsd not to record changes on that volume.
- Node ID (FSEvents)
- The file system object ID stored in 2SLD and 3SLD FSEvents records; it follows a file across renames and moves.
- Quarantine attribute (com.apple.quarantine)
- The extended attribute macOS adds to downloaded files so Gatekeeper checks them on first open; removing it skips that check.
- TCC database (TCC.db)
- The SQLite databases where macOS records privacy permissions such as Full Disk Access, camera or screen recording.