Hi
I'm Trying logging deleted all file through sysmon.
I used this sysmon config xml and latest sysmon.exe
--------------------sysmon config------------------------
<Sysmon schemaversion="4.70">
<DnsLookup>False</DnsLookup>
<EventFiltering>
<FileDeleteDetected onmatch="exclude">
</FileDeleteDetected>
</EventFiltering>
</Sysmon>
I think If deleted any file, logging event id 26 include deleted file.
But, event ID 26 not logging after delete any path directory, file.
Only the following two are logged repeatedly.
I don want this target file name
how can I logging deleted all file through sysmon?