look for those event codes: 4728 4729 4732 4735 4737 4378 4756 4757
then write your own logic ...
i think there are plenty of answers in this forum regarding changes in groups with windows event codes
see here to get an idea of use cases and how to work with the event codes data:
https://answers.splunk.com/answers/222668/monitor-ad-group-changes.html
https://answers.splunk.com/answers/558526/find-out-who-changed-an-ad-account-password.html
https://answers.splunk.com/answers/132146/ad-user-groups.html
hope it helps
... View more