# Windows File Server

**URL:** <https://discuss.elastic.co/t/windows-file-server/71014>\
**Category:** Logstash\
**Created:** [January 10, 2017, 4:03am UTC](https://discuss.elastic.co/t/windows-file-server/71014 "2017-01-10T04:03:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hassan\_Nashrah](https://avatars.discourse-cdn.com/v4/letter/h/51bf81/32.png) [@Hassan\_Nashrah](https://discuss.elastic.co/u/Hassan_Nashrah)\
**Post date:** [January 10, 2017, 4:03am UTC](https://discuss.elastic.co/t/windows-file-server/71014/1 "2017-01-10T04:03:19Z")

</div>

I need to monitor which user accessed which files in network share. at offline times. from windows file server is there a way i can get this information and send to ELK to monitor.

i need to grab their IP address/AD username and time accessed + timestamps

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 10, 2017, 7:15am UTC](https://discuss.elastic.co/t/windows-file-server/71014/2 "2017-01-10T07:15:00Z")

</div>

If Windows is able to log this information I'm sure Logstash or a one of the beats can pick it up, but the question of how to get Windows to log this is better asked elsewhere.

---

<div class="post-metadata">

**Author:** ![Hassan\_Nashrah](https://avatars.discourse-cdn.com/v4/letter/h/51bf81/32.png) [@Hassan\_Nashrah](https://discuss.elastic.co/u/Hassan_Nashrah)\
**Post date:** [January 10, 2017, 8:24am UTC](https://discuss.elastic.co/t/windows-file-server/71014/3 "2017-01-10T08:24:45Z")

</div>

Yes I know . searched internet whether its available in windows.. thought someone might have an answer here or implementation done as such so could give me the answer

---

<div class="post-metadata">

**Author:** ![nick.e](https://avatars.discourse-cdn.com/v4/letter/n/8dc957/32.png) [@nick.e](https://discuss.elastic.co/u/nick.e)\
**Post date:** [January 10, 2017, 8:45am UTC](https://discuss.elastic.co/t/windows-file-server/71014/4 "2017-01-10T08:45:22Z")

</div>

Windows Event Log is a large topic and it would be too much to write a whole guide on how to do exactly what you want, but in short you have to do these three steps:

1. You have to enable auditing File System events in Windows and configure a SACL. A good basic guide can be found [here](https://blogs.technet.microsoft.com/mspfe/2013/08/26/auditing-file-access-on-file-servers/):

2. Use [Winlogbeat](https://www.elastic.co/guide/en/beats/winlogbeat/current/index.html) to send the Windows Events generated by the enabled auditing (1) to your Logstash/Elasticsearch instance.

3. Then you can search for the event with the event\_id [4663](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4663) in Elasticsearch. This event is generated when an object you configured in the SACL is accessed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2017, 8:45am UTC](https://discuss.elastic.co/t/windows-file-server/71014/5 "2017-02-07T08:45:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
