I need to create a rule in this language that will trigger an alert every time a new user is created in GCP.
I need the rule to be suitable for the Chronicle environment.
I tried to do this -
rule new_user_creation{
meta:
author = "test"
description = "Alert when a new user created"
events:
$create.target.user.userid = $user
$create.metadata.event_type = "USER_CREATION"
condition:
$create
}
Thank you