I am trying to take the records to create user account, delete user account and modify user account.
I have also been asked to take audit events on files and folders, this send it to logstash.
I have already installed winlogbeat and it is already sending data to logstash and this to elasticsearch but I do not know which event corresponds to each of the aforementioned actions, my knowledge of log log storage in windows is null.
I don't know if anyone has had the same problem, thank you very much.