File Accesses in a Windows Environment by user WinEventLog:Security Go Splunk 1 0 File Accesses in a Windows Environment by user sourcetype="WinEventLog:Security" user=* (EventCode=560 OR EventCode=4656) | chart count by Type 1 sourcetype="WinEventLog:Security" user=* (EventCode=560 OR EventCode=4656) | chart count by Type Continue Reading →