List of DELETED files from windows event log


(Aleksander Pedersen) #1

How can I make a query to get a list of DELETED files from windows event log?
The event structure is a bit complex. An event whit event_id:4660 telling "An object was deleted.". but not what object.

The complexity is explained a little more her https://eventlogxp.com/blog/tracking-down-who-removed-files/


(Thiago Souza) #2

Are you referring to a query in Elasticsearch? Or a query directly in windows event log?


(system) #3

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.