Getting Data In

who had access to a specific directory?

AlessandroMagno
Engager

Hi,

I should known, with Splunk, who had access to a specific directory in our fileserver.

Questions:
- what should be the query?
- before those query should I able the audit control in those specific folder directory?

Thanks,
AM

0 Karma

BobM
Builder

In windows, you need to turn object auditing for the folder you are monitoring. Windows will then log events in the windows security log. Assuming you are splunking this, you can start searching for events.

bmacias84
Champion

Are trying to get ACLs for each folder on our file server or do you want to track changes to specific folder? I am assuming this is windows server or workstation.

0 Karma

AlessandroMagno
Engager

Hi krugger,

our fileserver is Windows 2003.
Audit are actived, maybe I should check the Splunk Forwarder into our fileserver.

Thanks!

0 Karma

krugger
Communicator

What kind of file server are we talking about?
Windows, Linux or something else? It has to be in the logs for splunk to pick it up, so you need to have an audit somewhere.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...