FileMonitor: file access
Find out who read, changed, deleted or renamed a file on a file server, and choose which folders are monitored.
FileMonitor records file access on Windows file servers: read, write, delete, rename, move, copy. It is mostly used to find out who deleted something, or to spot unusual activity on a share.
Finding an access
In Events (#/events), type a file name or a user name in Search file, user..., then filter if needed by operation (Read, Write, Delete, Rename, Move, Copy), by agent (the server) and by date. Click a row for the details: Source IP, Source Machine, Process, PID, Size, Agent.
The counters at the top cover the last 24 hours. Export produces a CSV file (semicolon-separated, opens in Excel) capped at 10,000 rows; if the file is cut short, narrow the period.
Activity per user
Users (#/file-users) ranks accounts by activity over 1 h, 6 h, 24 h, a week or a month: number of events, files touched, operations, last activity. View events opens the list already filtered.
Choosing what is monitored
Monitored Paths (#/paths) shows one card per server. The Edit button lets you Add path (the folders to monitor), Add exclusion (*.tmp or a full path) and Add user to ignore (DOMAIN\name), typically the backup account.
The Pending update badge disappears once the agent has picked up the new configuration, within a minute.
Global Filters (administrators) hide access under C:\Windows and to AutoRun.inf files by default. They only affect what is displayed; collection carries on.
Server prerequisites
The agent must be installed with FILEMONITOR=true, or the module enabled in FSI Agents.
Windows auditing must be on: object access (event 4663, local access) and detailed file share (5145, network access, which gives the client address), with SACLs on the monitored folders. The agent can set the audit policy and the SACLs itself if the auditSetupEnabled option is turned on in its configuration.
Identical accesses close together are grouped over a 30-second window, so they do not flood the screens.
Alerts
FileMonitor does not raise alerts itself; the SIEM uses its events:
| Rule | Severity | Trigger |
|---|---|---|
| SEC-RANSOM-001 | critical | 10 writes or renames in 5 min to ransomware extensions (.encrypted, .locked…) |
| SEC-RANSOM-002 | critical | 100 writes, renames or deletes in 10 min |
| INFRA-STOR-002 | high | 50 deletes in 5 min by the same user on the same machine |
| GDPR-004 | high | 100 deletes in 5 min |
These rules are turned on under SIEM → Rules.
Frequently asked questions
I don't see any events. Check in this order: the module is active on the agent, paths are defined, Windows auditing and SACLs are in place, and the user you are looking for is not in the exclusions.
I changed a path and nothing happens. The agent applies the configuration at its next heartbeat, within a minute.
I can't see access to C:\Windows. It is hidden. Tick Show C:\Windows events under Global Filters.
Source: · FirstSI Docs · updated 2026-10-10