Hello,
Is the IT essentials work app able to provide all the functionalities that the now deprecated splunk app for windows infraestructure did?
In detail, we use the former to alert when a user has group membership changes in Active Directory for specific groups.
The data we use for this comes from the WinEventLog:Security source.
Thanks.
I do not have the answer to your first question.
But below are the two Apps that have the alert that you are looking for (Group membership changes)