Glossary
Node ID (FSEvents)
The file system object ID stored in 2SLD and 3SLD FSEvents records; it follows a file across renames and moves.
The node ID is the 8-byte identifier of the file system object stored in each FSEvents record from the 2SLD format onwards (macOS 10.13 High Sierra and later). On APFS it corresponds to the inode number, the same value ls -i or stat shows for a file that still exists. Older 1SLD records have no node ID.
Why it matters in investigations
A rename or move keeps the object, so it keeps the node ID. FSEvents logs a rename as two records, one with the old path and one with the new path, both flagged Renamed; the shared node ID is what ties them together. That lets you:
- pair renames reliably, instead of guessing from consecutive event IDs;
- follow a file across names, from a browser's temporary download name to the final one, or from a
.tmpfile to a LaunchAgent; - tie records together when a path was reused by a different object, or when the same object appears under several paths.
Node IDs can be reused after a file is deleted, so compare them within a short span of event IDs, and confirm with the path and flags. If the file still exists, its current inode number can link the FSEvents history to the live file system.
Example
In the synthetic sample, Safari downloads tools.zip into a .download bundle, then moves it:
Users/dana.whitlock/Downloads/tools.zip.download/tools.zip:Renamed;FileUsers/dana.whitlock/Downloads/tools.zip:Renamed;File, same node ID
The FSEvents Parser pairs both sides in its Renames tab, paired by node ID, and typing node: followed by the ID in the search box shows every record of that object.
Related terms
Follow node IDs in the FSEvents Parser; the record layout per version is in FSEvents file format: 1SLD, 2SLD and 3SLD pages.