I have not seen any direct link to display this but you could add a portal agent config for each group. just clone the default config (if you have one ) and add each group to the config selection criteria.
So your portal would have an agent config named "HOD" and the user/user group under selection criteria would also be "HOD".
you will then be able to run a custom report on GlobalProtect and use the filter builder "Description Contains HOD"
Or... If you are forwarding to syslog then you could import all group members into a file and using a "while do" loop grep the logs.