File Deletion Attempts In Windows

The following splunk queries will return results based on any user account who attempts to delete a file. This will return both successful and failed attempts.

Ensure the Splunk App for Windows is installed grab it here:

Windows 2003 and older:

Windows 2008 and newer:


Share This:

Leave A Comment?