Request to AD when receiving an event

Hello everyone. There is a task: when a certain event arrives in opensearch, you need to request information in ad. Let’s say the user account is logged into the server. You need to request a list of groups in ad. As far as I understand, this can be implemented either through enrichment in logstash, or by running external scripts via a webhook in alerts. Perhaps there are some other easier options, or someone has already done this. Please share your experience.