Splunk Search

How to write a search to find who deleted or modified files on a Windows server for the last 24 hours?

mattkun
New Member

I am now very new to Splunk. I have installed a Splunk forwarder to monitor Window Security Logs, but would like also build a search to search who deleted and modified files / folder for the last 24 hours. Please point me to the right direction. Also, is it possible to prompt asking to enter the server name or file name when the search is running? Thanks.

0 Karma

javiergn
Super Champion

Hi,

Before you can write a search to find out who deleted or modified files on Windows server, you need to enable some sort of file auditing.
Three options currently in Splunk:

  1. Enable Windows native file auditing via security event logs and then tell Splunk to monitor those logs. See this link.
  2. Use a third party tool to monitor file changes and point Splunk to the relevant logs.
  3. Use Splunk Enterprise File Change Monitor (deprecated so not recommended for a long term solution). See this link.

In terms of performance, because we wanted to monitor any type of file operation, which includes millions of log entries per hour in some servers, we decided to go for a 3rd party enterprise agent that was known to have a low impact in your server performance, but in your case I would probably go for the native Windows file auditing via event logs.

Once you have your event logs coming into Splunk, simply filter by the relevant index, sourcetype, host and EventCodes based on the Event IDs used by Windows auditing. See this link again for more information.

Hope that helps.

Thanks,
J

0 Karma

renjith_nair
Legend

start with

index=<your index> EventCode=<event code for your operation> host=<servername you want> earliest=-24h

References :

http://docs.splunk.com/Documentation/Splunk/6.2.0/SearchReference/WhatsInThisManual
http://docs.splunk.com/Documentation/Splunk/6.2.0/Search/GetstartedwithSearch
http://docs.splunk.com/Documentation/Splunk/6.2.0/SearchReference/ListOfSearchCommands

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...