As the question stated I am trying to create an alert that lets me know when Domain admins were added or removed from the
Domain group. I also need the alert to create a table that displays the Domain, User, and Workstation.
This is the search I am currently using.
index=* Group_Name=Administrators Administrators* EventCode=4732
| eval delta=now()-latest
| rangemap default=missing field=delta current=0-90000
| convert ctime(latest) AS "Last Indexed"
| table user, sourcetype, host | rename host as Workstation