need to create an alert which triggers whenever an User is added to splunk instance.
For local users, you can find creation events with this:
index=_audit action=edit_user operation=create
For users added to LDAP or other external authentication services you'll need to look at the logs from that source, Splunk doesn't log a "one of the groups in an LDAP server I'm connected to has gained a user" event.