Synopsis
SIEM Pull Service has detected via Splunk query that, on this Linux system, a user was added to a group.
Description
SIEM Pull Service has detected via Splunk query that, on this Linux system, a user was added to a group. The query used was (sourcetype=linux_audit OR sourcetype=linux_secure) AND ("op=adding user to group" OR add-user-to-group)