File Accesses in a Windows Environment by user WinEventLog:Security Go Splunk 1 0 File Accesses in a Windows Environment by user sourcetype="WinEventLog:Security" user=* (EventCode=560 OR EventCode=4656) | chart count by Type 1 sourcetype="WinEventLog:Security" user=* (EventCode=560 OR EventCode=4656) | chart count by Type Share This: Tagged: 6.1.2Access AttemptsFile AccessSecurityWindowsWindows Security