{"id":1366,"date":"2014-07-30T02:45:29","date_gmt":"2014-07-30T07:45:29","guid":{"rendered":"http:\/\/swildow.darktech.org\/wp\/?p=1366"},"modified":"2014-07-30T02:45:29","modified_gmt":"2014-07-30T07:45:29","slug":"use-auditing-to-track-who-deleted-your-files","status":"publish","type":"post","link":"https:\/\/www.wildow.com\/blog\/?p=1366","title":{"rendered":"Use auditing to track who deleted your files"},"content":{"rendered":"<div class=\"headline_area\" style=\"color: #054865; font-family: Thanoma, sans-serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;\">\n<h1 class=\"entry-title\" style=\"color: #0081bc; font-size: 20px;\">Use auditing to track who deleted your files<\/h1>\n<p class=\"headline_meta\" style=\"color: #000000; font-size: 14px; font-style: italic;\">by<span class=\"Apple-converted-space\">\u00a0<\/span><span class=\"author vcard\" style=\"font-style: normal;\"><a class=\"url fn\" style=\"color: #054865;\" href=\"http:\/\/www.intelliadmin.com\/index.php\/author\/steve-wiseman\/\">Steve Wiseman<\/a><\/span><span class=\"Apple-converted-space\">\u00a0<\/span>on<span class=\"Apple-converted-space\">\u00a0<\/span><abbr class=\"published\" style=\"font-style: normal;\" title=\"2008-03-21\">March 21, 2008<\/abbr><span class=\"Apple-converted-space\">\u00a0<\/span>\u00b7<span class=\"Apple-converted-space\">\u00a0<\/span><span style=\"font-style: normal;\"><a style=\"color: #054865;\" href=\"http:\/\/www.intelliadmin.com\/index.php\/2008\/03\/use-auditing-to-track-who-deleted-your-files\/#comments\" rel=\"nofollow\">27 comments<\/a><\/span><\/p>\n<p class=\"headline_meta\" style=\"color: #000000; font-size: 14px; font-style: italic;\">in<span class=\"Apple-converted-space\">\u00a0<\/span><span style=\"font-style: normal;\"><a style=\"color: #054865;\" title=\"View all posts in Windows\" href=\"http:\/\/www.intelliadmin.com\/index.php\/category\/windows\/\" rel=\"category tag\">Windows<\/a><\/span><\/p>\n<\/div>\n<div class=\"format_text entry-content\" style=\"font-size: 16px; line-height: 23px; overflow: hidden; width: 578.1875px; margin-bottom: 10px; word-wrap: break-word; color: #054865; font-family: Thanoma, sans-serif; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;\" data-find=\"_1\"><a href=\"http:\/\/www.intelliadmin.com\/index.php\/2008\/03\/use-auditing-to-track-who-deleted-your-files\/\" target=\"_blank\">http:\/\/www.intelliadmin.com\/index.php\/2008\/03\/use-auditing-to-track-who-deleted-your-files\/<\/a><br \/>\nI had a reader write me a few days ago:<\/p>\n<p><i>\u2026I\u2019m in a school environment and a student has deleted some files and I would like to know how I can do this in Win2k server to catch this sucker. Please advice and more power to you.<\/i><\/p>\n<p>&nbsp;<\/p>\n<p>This can be accomplished through auditing. Lets start out by identifying what folder we want to watch \u2013 and be careful where you turn on auditing\u2026turn it on too many folders with too many options and you can have huge performance issues.<\/p>\n<p>We find the folder we want, and right click on it and go to properties<\/p>\n<p><img decoding=\"async\" style=\"border: 0pt;\" src=\"http:\/\/www.intelliadmin.com\/images\/Audit%20For%20Deleted%20Files%20Properties.jpg\" alt=\"Audit For Deleted Files Properties\" \/><\/p>\n<p>This will bring up the properties page for the folder. Move over to the security tab, and click on the advanced button:<\/p>\n<p><img decoding=\"async\" style=\"border: 0pt;\" src=\"http:\/\/www.intelliadmin.com\/images\/Audit%20For%20Deleted%20Files%20Properties%20Page.jpg\" alt=\"Audit For Deleted Files Properties Page\" \/><\/p>\n<p>The advanced page will appear. Click on the Auditing tab, and click the add button:<\/p>\n<p><img decoding=\"async\" style=\"border: 0pt;\" src=\"http:\/\/www.intelliadmin.com\/images\/Audit%20For%20Deleted%20Files%20Advanced.jpg?1\" alt=\"Audit For Deleted Files Advanced\" \/><\/p>\n<p>A user dialog will come up. I chose to put the \u201cEveryone\u201d group here. This allows me to audit for any possible user account that may be deleting files. If you think you know who it might be\u2026you could put those users here instead. The smaller window of users being audited means better performance.<\/p>\n<p><img decoding=\"async\" style=\"border: 0pt;\" src=\"http:\/\/www.intelliadmin.com\/images\/Audit%20For%20Deleted%20Files%20User%20Selection.jpg\" alt=\"Audit for Deleted Files User Selection\" \/><\/p>\n<p>Once you click OK, a selection box will be displayed. Again \u2013 chose only the options you need. Each additional option will reduce performance. Here I just pick the options to audit deleting files and folders<\/p>\n<p><img decoding=\"async\" style=\"border: 0pt;\" src=\"http:\/\/www.intelliadmin.com\/images\/Audit%20For%20Deleted%20Files%20Event%20Selection.jpg\" alt=\"Audit For Deleted Files Event Selection\" \/><\/p>\n<p>Click OK through all of the windows you have open. If a user deletes a file or folder Windows will write an event to the security log.<\/p>\n<p>Now. We have our auditing turned on, and you get to work one morning and find that files are missing. Simply open the event viewer and move over to the security log. Look for the event ID 560:<\/p>\n<p><img decoding=\"async\" style=\"border: 0pt;\" src=\"http:\/\/www.intelliadmin.com\/images\/Audit%20For%20Deleted%20Files%20Security%20Event%20560.jpg\" alt=\"Audit For Deleted Files Security Event 560\" \/><\/p>\n<p>Double click on the event, and you will need to sit there and read it for a little bit to determine who did what. Here is an excerpt from mine (I copied the text from event viewer to notepad for easier reading)<\/p>\n<p><img decoding=\"async\" style=\"border: 0pt;\" src=\"http:\/\/www.intelliadmin.com\/images\/Audit%20For%20Deleted%20Files%20Security%20Event%20560%20View.jpg\" alt=\"Audit For Deleted Files Security Event 560 View\" \/><\/p>\n<p>We can see from this log entry that the user Administrator deleted the file setuperr.log<\/p>\n<p>Now when someone deletes a file, you will have no problem determining who did it.<\/p>\n<p>If you have a windows administration question, or an idea for a utility please send me an email at<span class=\"Apple-converted-space\">\u00a0<\/span><a style=\"color: #054865;\" href=\"mailto:support@intelliadmin.com\">support@intelliadmin.com<\/a>. I can\u2019t promise that I will answer every email, but I try to read them all.<\/p>\n<div class=\"blogger-post-footer\"><a style=\"color: #054865;\" href=\"http:\/\/www.intelliadmin.com\/downloads.htm\">Check out our Windows Admin Tools<\/a><\/div>\n<p>One more thing\u2026Subscribe to my newsletter and get 11 free network administrator tools, plus a 30 page user guide so you can get the most out of them.<span class=\"Apple-converted-space\">\u00a0<\/span><a style=\"color: #054865;\" href=\"http:\/\/www.intelliadmin.com\/index.php\/network-administrator-tool-kit\/\">Click Here to get your free tools<\/a><\/p>\n<\/div>\n<p><!--more--><\/p>\n<p><!--more--><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Use auditing to track who deleted your files by\u00a0Steve Wiseman\u00a0on\u00a0March 21, 2008\u00a0\u00b7\u00a027 comments in\u00a0Windows http:\/\/www.intelliadmin.com\/index.php\/2008\/03\/use-auditing-to-track-who-deleted-your-files\/ I had a reader write me a few days ago: \u2026I\u2019m in a school environment and a student has deleted some files and I would &#8230; <a class=\"more-link\" href=\"https:\/\/www.wildow.com\/blog\/?p=1366\">Read More &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1366","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/www.wildow.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1366","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wildow.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wildow.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wildow.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wildow.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1366"}],"version-history":[{"count":1,"href":"https:\/\/www.wildow.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1366\/revisions"}],"predecessor-version":[{"id":1367,"href":"https:\/\/www.wildow.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1366\/revisions\/1367"}],"wp:attachment":[{"href":"https:\/\/www.wildow.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1366"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wildow.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1366"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.wildow.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1366"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}