Windows File Share Auditing Rules

Version 1

    Rules designed to trigger when a Windows Share is created (event 5142), Modified (5143) or Deleted (5144).

     

    You need to have "File Share" auditing set to capture success in your audit policy for these events to be logged.  The LEM Agent will need to be on the machine in question to capture the events.