Glossary
fseventsd-uuid
The file in .fseventsd holding the UUID of a volume's event stream; a new UUID means a new FSEvents history.
fseventsd-uuid is a small text file in each .fseventsd folder. It contains a UUID that identifies the volume's event stream: the history that fseventsd has been writing to that folder. Log files and the records they hold only make sense within one stream.
Why it matters in investigations
Two facts make this file useful.
First, a new UUID starts a new history. After a reformat, a reset of the .fseventsd folder or the first time fseventsd sees a volume, a new stream begins and earlier records are gone. If the history looks shorter than expected, the UUID file explains why.
Second, the file's modification time marks when that history began. The FSEvents Parser uses it as the lower bound of the time window for the oldest log file, since there is no earlier file to bound it. On a busy Mac that bound can be months before the first log; on an external drive it is often very close.
A recent UUID on a USB stick suggests it was first attached to a Mac at that time, or that its FSEvents folder was reset then. The same UUID seen on two collections of one drive shows they belong to the same history.
Keep the file's modification time when collecting: tar, ditto and cp -p preserve it, many transfers do not.
Example
In the synthetic sample, the EXFIL stick's .fseventsd/fseventsd-uuid holds A0C47E19-2D3B-4F5A-9E8D-7C6B5A493827 and was last modified at 10:31:14 UTC, two seconds after the Mac's Data volume logged Volumes/EXFIL as mounted. The stick's history starts there, and the parser reports it as a history start finding.
Related terms
See the history start of each volume in the FSEvents Parser's Sources tab, and how it bounds time in dating FSEvents records.