<!--
{
  "availability" : [
    "macCatalyst: -",
    "macOS: -"
  ],
  "documentType" : "symbol",
  "framework" : "EndpointSecurity",
  "identifier" : "/documentation/EndpointSecurity/es_message_t/seq_num",
  "metadataVersion" : "0.1.0",
  "role" : "Instance Property",
  "symbol" : {
    "kind" : "Instance Property",
    "modules" : [
      "Endpoint Security"
    ],
    "preciseIdentifier" : "c:@SA@es_message_t@FI@seq_num"
  },
  "title" : "seq_num"
}
-->

# seq_num

The sequence number of the message.

```
var seq_num: UInt64
```

## Discussion

Inspect the sequence number per-client and per-event-type to detect whether the kernel had to drop events for this client. If the kernel doesn’t drop any events for this client, `seq_num` increments by 1 for every message of that event type.

To determine whether the kernel dropped events, compare the previous value of `seq_num` for this event type to the value received in the latest message. When the kernel drops no events, the difference is 1, since the current message increments the counter. You can therefore calculate the number of dropped messages as follows:

```c
numberOfDroppedEvents = thisMessage.seq_num - (prevMessage.seq_num + 1)
```

Dropped events generally indicate that the kernel generated more events than the client could handle.

This field is available if the message version is greater than `2`.

> Tip:
> For an equivalent counter that filters only by client and not event type, see ``doc://com.apple.endpointsecurity/documentation/EndpointSecurity/es_message_t/global_seq_num``.

---

Copyright &copy; 2026 Apple Inc. All rights reserved. | [Terms of Use](https://www.apple.com/legal/internet-services/terms/site.html) | [Privacy Policy](https://www.apple.com/privacy/privacy-policy)