1 of 1 people found this helpful
the audit for the user who deleted the object will have a "delete object" record - you just need to know the object ID.
Simplest thing would be to dump the user audit for all your users and the event 01000085 using the command line api. Then you should be able to search for your object ID (class 1 for user, 2 for machine) and see who did the dirty.
Fantastic, thank you!