how to get an alert when a file is deleted.what is the exact command for that search
What do you mean, when a file is deleted? A file on an OS? If so what OS, and what auditing do you have for that OS? A file on Splunk? Splunk event data?
Hi ,
Please create the alert based on this
index=_audit "action=search" search=*delete*