Windows File Access Attempts

The following splunk queries will display any file access attempts (successful or failed) by user account.

Ensure the Splunk App for Windows is installed grab it here: https://apps.splunk.com/app/742/

Windows 2003 and older:

Windows 2008 and newer:
Share This:

Leave A Comment?