FSEvents
Also called fseventsd, macOS file system events, .fseventsd.
- PLATFORM
- macOS
- CATEGORY
- File and Folder Access
- INDEX
- 9 of 36
- PROVES
- 5 findings
- CANNOT PROVE
- 5 limits
- QUESTIONS
- 3 answered
A per-volume macOS log of directory-level change notifications recording that paths were created, renamed, modified or removed — ordered by event identifier rather than by clock time.
Where it lives
/.fseventsd on each mounted volume, one compressed log file per batch
Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of fsevents” is neither.
What it records
The file system events daemon writes compressed logs recording a path and a set of change flags for each notification, so an examiner can see that a path was created, renamed, had its content modified, had its inode metadata changed, or was removed. The records are sequenced by a monotonically increasing event identifier. Individual records do not carry their own wall-clock timestamps; timing is inferred from the containing log file's own dates and from anchoring events, which is the single most important limitation of the artifact.
What it proves — and what it cannot
These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.
What it proves
FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.
- That a path existed on the volume and was created, renamed, modified or removed, even where the file is long gone
- The order in which changes occurred, from the event identifier sequence
- That a volume was mounted and written to, including external volumes that keep their own log
- Directory structures that no longer exist, reconstructed from the paths in the records
- Bulk activity patterns — a large number of creations under one directory tree in a short identifier range
What it cannot prove
INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.
- When any individual event happened. Records carry no per-event wall-clock time; timing comes from the log file's own dates and from anchoring against other artifacts, and an examiner who states an FSEvents record to the minute has supplied precision the format does not contain
- Which user or which process made the change. There is no account or process attribution anywhere in the record
- What a file contained, or that content was read. Only paths and change flags are stored
- That a copy occurred. A creation flag on a destination volume is consistent with a copy and equally consistent with a save, a download, or an application writing its own file
- A complete history. Logs are purged as the volume fills and are removed on some maintenance paths, so an absent record is not an absent event
How the finding is attacked
An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.
- Pressing on the absence of per-event timestamps and the assumptions used to place records on a clock
- Showing that the flags do not distinguish a user action from an application or system process doing the same thing
- Establishing how far back the surviving logs on the volume reach and whether that covers the period at issue
- Questioning whether the parser correctly resolved flag combinations, which are frequently coalesced into a single record for a path
What survives, and for how long
Logs live on the volume itself, so an external drive carries its own FSEvents history and can be examined even when the Mac cannot. They roll as space is reclaimed, and coverage on a busy volume can be short; a reformat removes them entirely.
More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.
Questions counsel ask
What does FSEvents prove on a Mac?
FSEvents proves that a path on that volume was created, renamed, modified or removed, and the order in which those changes happened relative to one another. It is the standard way to show that files and folders existed on a macOS volume after they have been deleted. It attributes nothing to a user or a process and records no file content.
Do FSEvents records have timestamps?
Not per record, and this is the most misunderstood point about the artifact. Individual entries are sequenced by an increasing event identifier, not stamped with a clock time. Timing is inferred from the dates of the log file containing them and by anchoring the sequence against events dated in other artifacts. Testimony placing an FSEvents record at a precise minute is asserting more than the format holds.
Can FSEvents show that files were copied to an external drive?
It can show that files with those paths were created on the external volume, if that volume's own FSEvents log survives and is examined. What it cannot do is establish that the creation was a copy rather than a save, a download, or an application writing its own data — and it identifies no user or process. The copy inference needs corroboration from the source machine.
Terms used on this page
Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.
Related artifacts
No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.
Spotlight Metadata Store
The macOS metadata index, holding per-file attributes including last-used dates, use counts, and the URL a downloaded file came from — often for files that no longer exist.
macOS Unified Logs
The macOS system-wide log stream, recording process launches, device attachment, authentication and application behaviour in extraordinary detail for a short period.
LSQuarantine
A per-user macOS database recording files downloaded by quarantine-aware applications, with the source URL, the downloading application, and a timestamp for each event.
$UsnJrnl (USN Change Journal)
A per-volume journal recording every change to every file — creation, deletion, rename, data overwrite — with a timestamp, a filename and a reason code for each entry.
Whether the fseventsevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.
A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.
- Can This Artifact Prove That?
Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.
- Computer forensics
The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.
- The artifact index
All 36 entries, grouped by what they bear on and filterable by platform.
- Daubert and digital evidence
Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.
Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.