Glossary
fseventsd (FSEvents)
fseventsd is the macOS daemon that records file system change events to the per-volume .fseventsd directory, a key source for file activity history.
fseventsd is the macOS daemon behind the FSEvents API. It records file system changes (creations, deletions, renames, modifications and more) and persists them to a hidden .fseventsd directory at the root of each volume, including external drives.
The logs are gzip-compressed page files containing records with a path, an event ID and a flags field; newer versions also store a node (inode) ID. Individual records carry no timestamp, so investigators estimate timing from the modification time of the log file that contains them and from event ID ordering.
FSEvents can reveal files that no longer exist, activity on removable media, and installer or malware staging. Parse them with FSEventsParser or mac_apt. See FSEvents forensics.