# Monitor Windows Filesystem changes

**URL:** <https://discuss.elastic.co/t/monitor-windows-filesystem-changes/354723>\
**Category:** Beats\
**Tags:** winlogbeat, auditbeat\
**Created:** [March 5, 2024, 11:03am UTC](https://discuss.elastic.co/t/monitor-windows-filesystem-changes/354723 "2024-03-05T11:03:42Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jonas\_S](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jonas_s/32/97631_2.png) [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Post date:** [March 5, 2024, 11:03am UTC](https://discuss.elastic.co/t/monitor-windows-filesystem-changes/354723/1 "2024-03-05T11:03:42Z")

</div>

Hello,

i want to monitor windows filesystem changes with elastic. I want to see what files are created and deleted by which user.

First i tried using auditbeat, which has the `event.action` which shows `update`, `deletes`, `create` and `move`. Exactly what i want to know. But the big problem is that the "who" is completely missing. The auditbeat documents contain no information about who performed the action.

So next i tried to use the windows events with winlogbeat. Those documents contain the user in `winlog.event_data.SubjectUserName`. But the big problem here is, that i could not figure out how to monitor file creation, moves, updates or renames.  
As far as i know the windows events do not contain any rename information whatsoever, instead if i create a new folder `C:\monitored path\test` i get a create child `4656` Event on `C:\monitored path\new folder` and a `4663` delete event on `C:\monitored path\new folder`. But `C:\monitored path\test` does not appear in the eventlog until something else happens with it, like deletion. In that case there would be a `4663` delete event on the path.

So i can monitor who deletes which files using winlogbeat, or which events happen using auditbeat, but so far i could not figure out how to monitor who creats, moves, updates or renames because of the way the windows filesystem works and auditbeat is missing the user information. Any idea how to do this with elastic?

Best regards  
Jonas

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 2, 2024, 1:04pm UTC](https://discuss.elastic.co/t/monitor-windows-filesystem-changes/354723/2 "2024-04-02T13:04:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
