Trying to find acccount whihc deleted a folder

This support forum board is for support questions relating to Nagios Log Server, our solution for managing and monitoring critical log data.
Locked
dlukinski
Posts: 1130
Joined: Tue Oct 06, 2015 9:42 am

Trying to find acccount whihc deleted a folder

Post by dlukinski »

Hello Nagios support

We are new customer, which have configured LOG servers and receiving logs for 2 weeks.
Got folder which was deleted back on 17th, but unable to query for event (do not know how)
- have folder name
- have 2 dates
- have event ID (must be 4660)

Somehow logs only come for today's date. Opening other dates logs do not help.
Unsure what to do
jolson
Attack Rabbit
Posts: 2560
Joined: Thu Feb 12, 2015 12:40 pm

Re: Trying to find acccount whihc deleted a folder

Post by jolson »

Are you sure that your Windows Server is logging folder deletion events?

If so, you should be able to query for the log as follows.

1. Navigate to 'Dashboard' and pick a timeperiod using the timeperiod button. Be sure to select a timeperiod during which the deletion event likely occured.
2015-11-23 13_42_40-Dashboard • Nagios Log Server.png
2. Find the 'EventID' field and apply it as a filter using the magnifying glass icon. (At this point the eventID does _not_ have to be the correct number).
2015-11-23 13_51_47-Dashboard • Nagios Log Server.png
3. Note that a new filter has been added to your search. You may now edit this filter and input the appropriate eventID.
2015-11-23 13_53_00-Dashboard • Nagios Log Server.png
2015-11-23 13_53_59-Dashboard • Nagios Log Server.png
Now press 'Apply'. The logs displayed are any logs matching eventID 4660. If you need to further filter down your log contents, make use of any field that you see as valuable (host may be another good filter to add).
You do not have the required permissions to view the files attached to this post.
Twits Blog
Show me a man who lives alone and has a perpetually clean kitchen, and 8 times out of 9 I'll show you a man with detestable spiritual qualities.
dlukinski
Posts: 1130
Joined: Tue Oct 06, 2015 9:42 am

Re: Trying to find acccount whihc deleted a folder

Post by dlukinski »

Thank you

Please close the case
bwallace
Posts: 1145
Joined: Tue Nov 17, 2015 1:57 pm

Re: Trying to find acccount whihc deleted a folder

Post by bwallace »

Glad we were able to help. We'll lock this thread now and feel free to open another should you require assistance with anything else.
Be sure to check out the Knowledgebase for helpful articles and solutions!
Locked