Hello,
I would like to create the alert that:
someone login to system (event login = successful login) and I just want to check if in 5 min from this event, was any user or group was created by user (which is not member of admin group).
or another version:
If X notification was triggered + notification about new user or new group was triggered (created not by admin)- but 1h before and 1h after notification X (timestamp), then: generate alert
Could you please provide some tips for this case?
Best regards,
Jacob