Skip to content
FirstSIDocs

FileMonitor: file access

Find out who read, changed, deleted or renamed a file on a file server, and choose which folders are monitored.

FileMonitor records file access on Windows file servers: read, write, delete, rename, move, copy. It is mostly used to find out who deleted something, or to spot unusual activity on a share.

Finding an access

In Events (#/events), type a file name or a user name in Search file, user..., then filter if needed by operation (Read, Write, Delete, Rename, Move, Copy), by agent (the server) and by date. Click a row for the details: Source IP, Source Machine, Process, PID, Size, Agent.

The counters at the top cover the last 24 hours. Export produces a CSV file (semicolon-separated, opens in Excel) capped at 10,000 rows; if the file is cut short, narrow the period.

Activity per user

Users (#/file-users) ranks accounts by activity over 1 h, 6 h, 24 h, a week or a month: number of events, files touched, operations, last activity. View events opens the list already filtered.

Choosing what is monitored

Monitored Paths (#/paths) shows one card per server. The Edit button lets you Add path (the folders to monitor), Add exclusion (*.tmp or a full path) and Add user to ignore (DOMAIN\name), typically the backup account.

The Pending update badge disappears once the agent has picked up the new configuration, within a minute.

Global Filters (administrators) hide access under C:\Windows and to AutoRun.inf files by default. They only affect what is displayed; collection carries on.

Server prerequisites

The agent must be installed with FILEMONITOR=true, or the module enabled in FSI Agents.

Windows auditing must be on: object access (event 4663, local access) and detailed file share (5145, network access, which gives the client address), with SACLs on the monitored folders. The agent can set the audit policy and the SACLs itself if the auditSetupEnabled option is turned on in its configuration.

Identical accesses close together are grouped over a 30-second window, so they do not flood the screens.

Alerts

FileMonitor does not raise alerts itself; the SIEM uses its events:

RuleSeverityTrigger
SEC-RANSOM-001critical10 writes or renames in 5 min to ransomware extensions (.encrypted, .locked…)
SEC-RANSOM-002critical100 writes, renames or deletes in 10 min
INFRA-STOR-002high50 deletes in 5 min by the same user on the same machine
GDPR-004high100 deletes in 5 min

These rules are turned on under SIEM → Rules.

Frequently asked questions

I don't see any events. Check in this order: the module is active on the agent, paths are defined, Windows auditing and SACLs are in place, and the user you are looking for is not in the exclusions.

I changed a path and nothing happens. The agent applies the configuration at its next heartbeat, within a minute.

I can't see access to C:\Windows. It is hidden. Tick Show C:\Windows events under Global Filters.

Source: · FirstSI Docs · updated 2026-10-10