1 **Phase 1: Completed pre-decoding.
2 full event: 'May 28 10:48:29 niban useradd[32421]: new group: name=logr, gid=12000'
4 program_name: 'useradd'
5 log: 'new group: name=logr, gid=12000'
7 **Phase 2: Completed decoding.
10 **Phase 3: Completed filtering (rules).
13 Description: 'New group added to the system'
14 **Alert to be generated.