source=WinEventLog:Security EventCode IN (4728, 4732, 4746, 4751, 4756, 4761, 4729, 4733, 4747, 4752, 4757, 4762, 4786, 4788) earliest=-7d@d
| eval changed_by=mvindex(Security_ID, 0)
| eval member_id=mvindex(Security_ID, 1)
| eval group_id=mvindex(Security_ID, 2)
| rex "A member was (?<change_type>(added|removed))"
| eval host_name=coalesce(src_nt_host, dvc_nt_host, host)
| rename EventCode as event_code EventCodeDescription AS event_desc
| table _time host_name changed_by change_type group_id member_id event_code event_desc
... View more