|
|
Forum Newbie
      
Group: Forum Members
Last Login: 8/21/2016 2:10:19 PM
Posts: 2,
Visits: 7
|
|
Hi. I am trying to identify deleted files. If I delete a file in network share (in windows 2012 r2), 4660 is not generated.
Normal file deletion is logging 4660. But deleting shared file does not generate the same event.
The event is generated well in windows server 2008.
Is there any alternate event in windows server 2012 r2?
|
|
|
|
Supreme Being
      
Group: Moderators
Last Login: 11/14/2013 3:17:47 PM
Posts: 237,
Visits: 0
|
|
Take a look at event ID 4663 and look for any "Delete" accesses.
|
|
|
|
Forum Newbie
      
Group: Forum Members
Last Login: 8/21/2016 2:10:19 PM
Posts: 2,
Visits: 7
|
|
Hi,
But after deletion 4663 is also not available. (This happens only for network share deletion)
|
|
|
|
Supreme Being
      
Group: Moderators
Last Login: 11/14/2013 3:17:47 PM
Posts: 237,
Visits: 0
|
|
Ensure that proper logging is enabled as outlined here: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4663.
|
|
|
|