Step 2: Edit auditing entry in the respective file/folder.
Locate the parent directory or folder in which you want to track creation and deletion of files/sub folders. Right click on it and go to Properties. Under the Security tab click Advanced.
Every time a user accesses the selected file/folder and changes the permission on it, an event log will be recorded in the Event Viewer. Under Windows Logs, select Security. You can find all the audit logs in the middle pane as displayed below.
To filter the event logs to view just the logs about the file/folders created and deleted, select Filter Current Log from the right pane. Simply search for the event ID 4656 which indicates that access handle to an object was requested.
Unfortunately, these filters don't simply give you a list of files/folders created. They would need to be coupled with access masks to understand exactly which files/folders were created or deleted.