Assuming you are using a Windows OS you could: 1) Enable security auditing for files/folders (this is done within the windows OS, can be enabled via group policy) 2) Use SplunkUniversalForwarder to monitor the Event Log for events 4660 & 4663 (see Splunk: Monitor file system changes on Windows)
... View more