Activate Files Check
This option can be enabled through the domain Group Policy by applying a filter only to the relevant machines under:
Advanced Configuration > Object Access > Audit File System.
The same setting can also be managed directly through the local policies of the file server or servers.

The audit scope must then be extended to the folder to be monitored.
From the folder Security > Advanced settings:

Here, additional controls can be defined for the folder. Different controls can be configured for individual users or groups.

Specifically:

These are the recommended controls for a comprehensive BusinessLog monitoring. The audit level can be reduced or expanded according to organisational guidelines.
ATTENTION:
All selected machines and users will be subject to monitoring. Avoid excessive use of this feature to prevent the generation of thousands of access logs per day.
Guide
NOTE FOR NETAPP ENVIRONMENTS:
For NetApp ONTAP systems, file control activation is not performed through the Windows policies described on this page.
In this case, BusinessLog acquires the events produced by NetApp through EVTX log files, configured in the
Settings > Plug In section.
The folders to be monitored must still be configured in the Functions > File Control section, specifying the root folders and the operations to control, such as read, write and delete.
