Glossary
FSEvents event ID
The 64-bit, ever-increasing counter stored with each FSEvents record; it orders changes but is not a timestamp.
The FSEvents event ID is the 64-bit number stored with every FSEvents record. It is taken from a system-wide counter that only increases, so each new change on a Mac receives a higher ID than the one before. Apps use it to ask fseventsd "what changed since ID X?", and forensic tools use it to put records in order. The names of the log files in .fseventsd are event IDs too, written as 16 hexadecimal digits.
Why it matters in investigations
The event ID gives a reliable order of changes, including across the volumes of one Mac: records from the Data volume and from a USB stick attached to that Mac draw from the same counter and can be merged into one sequence. That order survives even when everything else about time is lost, for example when a collection reset the log files' modification times.
It is not a timestamp. Two consecutive IDs can be a millisecond or a week apart, and gaps in the numbering are normal (changes on other volumes, events that were not logged). To place a record in time, use the modification times of the log files, which give a window rather than a moment. IDs from two different Macs are not comparable.
Inside one record, the event ID cannot resolve the order of merged changes: that is the effect of coalescing.
Example
A log file named 0000000012a44759 covers IDs up to about 0x12a44759 (FSEventsParser treats the name as the file's last event ID). If a LaunchAgent record in it has a lower ID than a TCC.db write, the plist was logged first, even though both share the same time window. The FSEvents Parser shows IDs in hex, sorts every view by them and flags log files whose name falls outside the IDs they contain.
Related terms
Sort records by event ID in the FSEvents Parser, and read dating FSEvents records without timestamps for how to add time.