Security

How can I determine who deleted a file from a shared drive?

rmyers1
New Member

Is anyone aware of a log file that could be referenced to determine who deleted a file form a share drive? We have a couple apps that monitor the active directory (AD) and share drive activity but cannot find anything related to additions, deletions, or modifications.

0 Karma

adonio
Ultra Champion

Like @cpetterborg mentioned, it can be done.
you will need to enable special auditing on the folders you would like to keep track off.
this is not the most dated article but it explains how to enable the right auditing policies.
https://blogs.technet.microsoft.com/mspfe/2013/08/26/auditing-file-access-on-file-servers/
now you can monitor with Splunk
again like mentioned above, the auditing settings will not work retroactively.
hope it helps a little

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

There are windows events that you can turn on that will look at specific files or directories for changes (fine grain auditing) that can be used to detect changes. They are not retroactive, however, and they have to be set up for each file or directory that you want to have changes logged. You also have to use the Windows App to get the WinEvents into Splunk.

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...