<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to achieve a search to detect a file deletion in fileserver? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-achieve-a-search-to-detect-a-file-deletion-in-fileserver/m-p/625996#M14621</link>
    <description>&lt;P&gt;Hello everyone and thanks in advance.&lt;/P&gt;
&lt;P&gt;I'm trying to make a search for file deletion but it isn't working.&lt;/P&gt;
&lt;P&gt;Do you have any example of a use case? I tested using sysmon but when I delete a file I can't see event 23.&lt;/P&gt;</description>
    <pubDate>Thu, 05 Jan 2023 17:37:14 GMT</pubDate>
    <dc:creator>msiri</dc:creator>
    <dc:date>2023-01-05T17:37:14Z</dc:date>
    <item>
      <title>How to achieve a search to detect a file deletion in fileserver?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-achieve-a-search-to-detect-a-file-deletion-in-fileserver/m-p/625996#M14621</link>
      <description>&lt;P&gt;Hello everyone and thanks in advance.&lt;/P&gt;
&lt;P&gt;I'm trying to make a search for file deletion but it isn't working.&lt;/P&gt;
&lt;P&gt;Do you have any example of a use case? I tested using sysmon but when I delete a file I can't see event 23.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 17:37:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-achieve-a-search-to-detect-a-file-deletion-in-fileserver/m-p/625996#M14621</guid>
      <dc:creator>msiri</dc:creator>
      <dc:date>2023-01-05T17:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: detect a file deletion in fileserver</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-achieve-a-search-to-detect-a-file-deletion-in-fileserver/m-p/626000#M14622</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248881"&gt;@msiri&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;at first you have to enable file monitoring on the File Server, but I don't know hot to do it.&lt;/P&gt;&lt;P&gt;Then, you'll have these information in the WinEventLog:Security&amp;nbsp; and you can search it: I don't know the EventCode, but you can ask it to the Windows Administator.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 13:32:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-achieve-a-search-to-detect-a-file-deletion-in-fileserver/m-p/626000#M14622</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-01-05T13:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: detect a file deletion in fileserver</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-achieve-a-search-to-detect-a-file-deletion-in-fileserver/m-p/626004#M14623</link>
      <description>&lt;P&gt;&lt;FONT size="3"&gt;Assuming you are using a Windows OS you could:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;1) Enable security auditing for files/folders (this is done within the windows OS, can be enabled via group policy)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;2) Use SplunkUniversalForwarder to monitor the Event Log for events 4660 &amp;amp; 4663 (see Splunk:&lt;A title="Monitor file system changes on Windows" href="https://docs.splunk.com/Documentation/Splunk/9.0.3/Data/MonitorfilesystemchangesonWindows" target="_self"&gt;&amp;nbsp;&lt;/A&gt;&lt;/FONT&gt;&lt;FONT size="3"&gt;&lt;SPAN class=""&gt;&lt;A title="Monitor file system changes on Windows" href="https://docs.splunk.com/Documentation/Splunk/9.0.3/Data/MonitorfilesystemchangesonWindows" target="_self"&gt;Monitor file system changes on Windows&lt;/A&gt;)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 13:56:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-achieve-a-search-to-detect-a-file-deletion-in-fileserver/m-p/626004#M14623</guid>
      <dc:creator>BryantRivera</dc:creator>
      <dc:date>2023-01-05T13:56:46Z</dc:date>
    </item>
  </channel>
</rss>

