# Auditing Windows file acccess

**URL:** <https://discuss.elastic.co/t/auditing-windows-file-acccess/101438>\
**Category:** Logstash\
**Created:** [September 22, 2017, 7:55am UTC](https://discuss.elastic.co/t/auditing-windows-file-acccess/101438 "2017-09-22T07:55:19Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![admlko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/admlko/32/21787_2.png) [@admlko](https://discuss.elastic.co/u/admlko)\
**Post date:** [September 22, 2017, 7:55am UTC](https://discuss.elastic.co/t/auditing-windows-file-acccess/101438/1 "2017-09-22T07:55:19Z")

</div>

Hi,

This didn't really fit into any of the categories, so I'll post it here.

I'm trying to audit windows file share accesses, but it seems to be quite hard, at least for me.  
I have found numerous resources which indicates that the interesting events are: 4656, 4658 and 4663.

However, I have not found a fool-proof way to indicate when someone has actually opened a file. I understand that this may be tricky when it comes to separate directory listing from read file event, but I am qurious how others have succeeded?

Write event is trivial, but read event is what I cannot figure out how to audit that.  
Currently, what happens is that if I browse to a directory which is in audit scope, it generates events indicating that I would have browsed to subdirectories, which I have not.

It is very important to get this right, as someone might get fired if the log shows that he/she has accessed a file.

A couple of resources:  
[https://www.splunk.com/blog/2013/07/08/audit-file-access-and-change-in-windows.html](https://www.splunk.com/blog/2013/07/08/audit-file-access-and-change-in-windows.html)  
[https://blogs.technet.microsoft.com/mspfe/2013/08/26/auditing-file-access-on-file-servers/](https://blogs.technet.microsoft.com/mspfe/2013/08/26/auditing-file-access-on-file-servers/)

Cheers!

---

<div class="post-metadata">

**Author:** ![admlko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/admlko/32/21787_2.png) [@admlko](https://discuss.elastic.co/u/admlko)\
**Post date:** [September 29, 2017, 10:47am UTC](https://discuss.elastic.co/t/auditing-windows-file-acccess/101438/2 "2017-09-29T10:47:55Z")

</div>

Anyone doing this?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 27, 2017, 10:48am UTC](https://discuss.elastic.co/t/auditing-windows-file-acccess/101438/3 "2017-10-27T10:48:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
