Ask the Expert

Using event logging to reveal network activity

Two computers' files were deleted remotely by another computer. How can we track down the source computer that logged into these two computer and deleted the files?
I'm not sure which version(s) of Windows you're running, but if you have security and system event logging enabled to track logins, network connections, etc. that may be your only source to track things down. See this Microsoft article for details on event logging. Also, consider any VPN, firewall, and router logs that may have recorded such events. Good luck in finding the perpetrator!

View questions and answers from all of our Windows security experts here.

This was first published in May 2006

There are Comments. Add yours.

 
TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
Sort by: OldestNewest

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to: