Glossary
no_log (.fseventsd)
An empty marker file in .fseventsd that tells fseventsd not to record changes on that volume.
no_log is an empty marker file in a volume's .fseventsd folder. When it is present, fseventsd does not keep a persistent history for that volume: no log files are written there. Some tools and administrators create it on external drives or other secondary volumes to avoid writing logs there.
Why it matters in investigations
A no_log file changes how an empty history must be read. Without it, a volume with no logs suggests the folder was deleted, the drive was never used on a Mac, or the collection missed it. With it, the absence of records is expected, and the question becomes when and why logging was disabled.
That question can matter. Disabling FSEvents on a drive right before copying data to it removes the list of files written, which is often the most valuable part of a USB exfiltration case. Check the marker's own timestamps, whether the volume's remaining logs stop around the same time, and what the Mac's own journal shows: the Data volume still logs the drive being mounted at Volumes/<name>, even when the drive itself keeps no history.
Always collect the whole .fseventsd folder, including no_log and fseventsd-uuid, so that this context is not lost.
Example
A USB stick's folder contains only:
.fseventsd/
fseventsd-uuid
no_log
The FSEvents Parser reports a no_log finding for that volume instead of silently showing zero records. On the Mac, Volumes/BACKUP with Mount;Folder and later Unmount;Folder still places the stick on the machine; what was written to it must come from other artifacts.
Related terms
Check each volume's status in the FSEvents Parser, and see what to collect in how to collect .fseventsd.