Security

How can I determine who deleted a file from a shared drive?

rmyers1
New Member

Is anyone aware of a log file that could be referenced to determine who deleted a file form a share drive? We have a couple apps that monitor the active directory (AD) and share drive activity but cannot find anything related to additions, deletions, or modifications.

0 Karma

adonio
Ultra Champion

Like @cpetterborg mentioned, it can be done.
you will need to enable special auditing on the folders you would like to keep track off.
this is not the most dated article but it explains how to enable the right auditing policies.
https://blogs.technet.microsoft.com/mspfe/2013/08/26/auditing-file-access-on-file-servers/
now you can monitor with Splunk
again like mentioned above, the auditing settings will not work retroactively.
hope it helps a little

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

There are windows events that you can turn on that will look at specific files or directories for changes (fine grain auditing) that can be used to detect changes. They are not retroactive, however, and they have to be set up for each file or directory that you want to have changes logged. You also have to use the Windows App to get the WinEvents into Splunk.

Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...