1 **Phase 1: Completed pre-decoding.
2 full event: 'May 21 10:24:54 niban useradd[6070]: new group: name=test, gid=5006'
4 program_name: 'useradd'
5 log: 'new group: name=test, gid=5006'
7 **Phase 2: Completed decoding.
10 **Phase 3: Completed filtering (rules).
13 Description: 'New group added to the system'
14 **Alert to be generated.