Alerting

How to achieve a search to detect a file deletion in fileserver?

msiri
Observer

Hello everyone and thanks in advance.

I'm trying to make a search for file deletion but it isn't working.

Do you have any example of a use case? I tested using sysmon but when I delete a file I can't see event 23.

Labels (1)
0 Karma

BryantRivera
New Member

Assuming you are using a Windows OS you could:

1) Enable security auditing for files/folders (this is done within the windows OS, can be enabled via group policy)
2) Use SplunkUniversalForwarder to monitor the Event Log for events 4660 & 4663 (see Splunk: Monitor file system changes on Windows)

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @msiri,

at first you have to enable file monitoring on the File Server, but I don't know hot to do it.

Then, you'll have these information in the WinEventLog:Security  and you can search it: I don't know the EventCode, but you can ask it to the Windows Administator.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...