event.dataset:"google_workspace.admin" and event.category:"iam" and event.action:"ASSIGN_ROLE"
and google_workspace.event.type:"DELEGATED_ADMIN_SETTINGS" and google_workspace.admin.role.name : *_ADMIN_ROLE
Install detection rules in Elastic Security
Detect Google Workspace Admin Role Assigned to a User in the Elastic Security detection engine by installing this rule into your Elastic Stack.
To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(opens in a new tab or window).