Skip to content

Glossary

no_log (.fseventsd)

An empty marker file in .fseventsd that tells fseventsd not to record changes on that volume.

no_log is an empty marker file in a volume's .fseventsd folder. When it is present, fseventsd does not keep a persistent history for that volume: no log files are written there. Some tools and administrators create it on external drives or other secondary volumes to avoid writing logs there.

Why it matters in investigations

A no_log file changes how an empty history must be read. Without it, a volume with no logs suggests the folder was deleted, the drive was never used on a Mac, or the collection missed it. With it, the absence of records is expected, and the question becomes when and why logging was disabled.

That question can matter. Disabling FSEvents on a drive right before copying data to it removes the list of files written, which is often the most valuable part of a USB exfiltration case. Check the marker's own timestamps, whether the volume's remaining logs stop around the same time, and what the Mac's own journal shows: the Data volume still logs the drive being mounted at Volumes/<name>, even when the drive itself keeps no history.

Always collect the whole .fseventsd folder, including no_log and fseventsd-uuid, so that this context is not lost.

Example

A USB stick's folder contains only:

.fseventsd/
  fseventsd-uuid
  no_log

The FSEvents Parser reports a no_log finding for that volume instead of silently showing zero records. On the Mac, Volumes/BACKUP with Mount;Folder and later Unmount;Folder still places the stick on the machine; what was written to it must come from other artifacts.

Check each volume's status in the FSEvents Parser, and see what to collect in how to collect .fseventsd.