What you need to check is auditing. Auditing is enabled on files/folders under security > advanced (when you right click a file/folder). I'm not too sure how you can check if auditing is enabled now that the objects have been deleted though. The only thing I can suggest is checking the parent folder(s) of those objects. I don't have much experience with auditing so somebody else may have some better suggestions.
If you want to start looking in the security log on your file server, maybe start off with this link:
First, determine what event ID(s) you're looking for. If any of those ID's exist in the log, then look at the data for the various entries. If they don't exist, then I think you're out of luck.
However, even if auditing was enabled on those objects, the events may have been overwritten by now, depending on (amongst other things):
- Your security log settings (ie, overwrite after x days or after a certain size)
- The amount of activity in the security log on the file server
- How long ago since the deletions took place
If you don't have any log management procedures in place, then this may be a very long and fruitless task I'm afraid
Sorry I couldn't be of more help. Maybe somebody else will be able to expand further on the above and help you out some more. Good Luck !!!
Irish Poetry - Karen O'Connor
Irish Poetry and Short Stories - Doghouse Books
Garten und Landschaftsbau