Hi,
To achieve this, we need to 1) enable file system auditing for the target computers; 2) crate a monitor/rule based on the specific Event ID generated above. For the step-by-step guide, we may refer to:
https://www.varonis.com/blog/windows-file-system-auditing/
https://infrontconsulting.asia/scom-create-monitor-based-on-event-viewer-log/
Note: the above articles are not from MS, just for your reference.
Regards,
Alex
If the response is helpful, please click "Accept Answer" and upvote it.