# \[WINLOGBEAT\] - Event :Delete folder or file

**URL:** <https://discuss.elastic.co/t/winlogbeat-event-delete-folder-or-file/224401>\
**Category:** Beats\
**Tags:** windows-installer, winlogbeat\
**Created:** [March 20, 2020, 10:51am UTC](https://discuss.elastic.co/t/winlogbeat-event-delete-folder-or-file/224401 "2020-03-20T10:51:12Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ekaduk](https://avatars.discourse-cdn.com/v4/letter/e/f1d935/32.png) [@ekaduk](https://discuss.elastic.co/u/ekaduk)\
**Post date:** [March 20, 2020, 10:51am UTC](https://discuss.elastic.co/t/winlogbeat-event-delete-folder-or-file/224401/1 "2020-03-20T10:51:12Z")

</div>

Hi, I'm a newbie user.  
I'd like to know if it could be possible to register a deletion of a file/folder in Windows, and then register it with winlogbeat.  
I've read the documentation about winlogbeat and I can't find something that goes down to the thing of file or folder deletion. What I have also read is this topic -\> [https://www.elastic.co/es/blog/monitoring-windows-logons-with-winlogbeat](https://www.elastic.co/es/blog/monitoring-windows-logons-with-winlogbeat)  
which is kind of a "nice to show" but "not clearly documented".  
Could you give me a grasp of understanging? Am I missing some obvious thing?  
Thanks in advance

---

<div class="post-metadata">

**Author:** ![Kim-Kruse-Hansen](https://avatars.discourse-cdn.com/v4/letter/k/f1d935/32.png) [@Kim-Kruse-Hansen](https://discuss.elastic.co/u/Kim-Kruse-Hansen)\
**Post date:** [March 20, 2020, 12:46pm UTC](https://discuss.elastic.co/t/winlogbeat-event-delete-folder-or-file/224401/2 "2020-03-20T12:46:31Z")

</div>

Hi

You need to enable audit on your windows file systems. Once auditing is enabled, you can use winlogbeat to collect audit events from the security log.

---

<div class="post-metadata">

**Author:** ![Kim-Kruse-Hansen](https://avatars.discourse-cdn.com/v4/letter/k/f1d935/32.png) [@Kim-Kruse-Hansen](https://discuss.elastic.co/u/Kim-Kruse-Hansen)\
**Post date:** [March 20, 2020, 12:48pm UTC](https://discuss.elastic.co/t/winlogbeat-event-delete-folder-or-file/224401/3 "2020-03-20T12:48:52Z")

</div>

Start here [https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/apply-a-basic-audit-policy-on-a-file-or-folder](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/apply-a-basic-audit-policy-on-a-file-or-folder)

---

<div class="post-metadata">

**Author:** ![ekaduk](https://avatars.discourse-cdn.com/v4/letter/e/f1d935/32.png) [@ekaduk](https://discuss.elastic.co/u/ekaduk)\
**Post date:** [March 23, 2020, 10:06am UTC](https://discuss.elastic.co/t/winlogbeat-event-delete-folder-or-file/224401/4 "2020-03-23T10:06:13Z")

</div>

Thanks for your fast answer Kim,  
And also for the information. But I've got a trouble setting up the audit. What happens is that Windows Security logs doesn't collect information about the folder i set to audit.  
The steps I made \>  
1 - Apply a basic audit policy in a folder (set it to deletions, create files, folders, etc.)  
2- In the local policyes of the server i want to audit, i set the System Access Control list properly.  
And that's all I made,  
Maybe do I need to restart the server? for such a little change?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 20, 2020, 10:06am UTC](https://discuss.elastic.co/t/winlogbeat-event-delete-folder-or-file/224401/5 "2020-04-20T10:06:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
