Getting Data In

who had access to a specific directory?

AlessandroMagno
Engager

Hi,

I should known, with Splunk, who had access to a specific directory in our fileserver.

Questions:
- what should be the query?
- before those query should I able the audit control in those specific folder directory?

Thanks,
AM

0 Karma

BobM
Builder

In windows, you need to turn object auditing for the folder you are monitoring. Windows will then log events in the windows security log. Assuming you are splunking this, you can start searching for events.

bmacias84
Champion

Are trying to get ACLs for each folder on our file server or do you want to track changes to specific folder? I am assuming this is windows server or workstation.

0 Karma

AlessandroMagno
Engager

Hi krugger,

our fileserver is Windows 2003.
Audit are actived, maybe I should check the Splunk Forwarder into our fileserver.

Thanks!

0 Karma

krugger
Communicator

What kind of file server are we talking about?
Windows, Linux or something else? It has to be in the logs for splunk to pick it up, so you need to have an audit somewhere.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...