Skip to content

Glossary

Event coalescing (FSEvents)

fseventsd merges several changes to the same path into one record, so one row can say Created, Modified and Removed.

Event coalescing is the way fseventsd merges several changes to the same path into a single record. The daemon buffers changes in memory before writing them to the current log file; when a path is touched several times within that buffer, it keeps one record whose flags are the union of everything that happened. A temporary file that was created, written and deleted before the next flush appears as one record flagged Created;Modified;Removed.

Why it matters in investigations

Coalescing changes how a timeline must be read:

  • The order inside a record is unknown. Created;Modified;Removed does not say the file was created first; the flags are a set, not a sequence.
  • Counts are not operations. One record can stand for many writes, so the number of records says nothing about how often a file was saved.
  • Order between records is still reliable. The event ID of each record comes from a counter that only goes up, so two records for different paths can be put in sequence with confidence.
  • A single record can hide a short life. A file that existed for seconds may leave only one row. That row is often the only trace of scratch files, installers or tools that clean up after themselves.

Report such a record as "the item was created and removed within this log's time window", not as a precise sequence.

Example

A record for private/tmp/stage.sh with the raw flags 0x00800013 decodes as Created, Removed and Modified on a file. The script existed, was written and was deleted, all before one flush. Its time window is the window of the log file that holds it, as described in dating FSEvents records. The FSEvents Parser lists files that appear and disappear in the loaded history under its short-lived files finding.

See how combined flags are decoded in the FSEvents Parser and in FSEvents flags explained.