Splunk Search

How to find who deleted the file from a folder?

innoce
Path Finder

Hello,

Can someone please help me with a query to find who deleted the files of users (user=x, y, z) from a folder. 

index=* sourcetype=* folder_name=*abc* 

Thankyou

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Can you post some sample data which shows those activities?

0 Karma
Get Updates on the Splunk Community!

Splunk Certification Support Alert | Pearson VUE Outage

Splunk Certification holders and candidates!  Please be advised of an upcoming system maintenance period for ...

Enterprise Security Content Update (ESCU) | New Releases

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...