How to build use case and notification for badge reader and domain?


Hi All,

How can I build a use case and get notified in Splunk when a user does not swipe his/her access card at the door but is logged into the domain?

Please help.

Labels (1)
Tags (2)
0 Karma


Hi Rich,

So I've managed to combine both the indexes but now the challenge I face is that results come in two separate rows instead of one. 

One row picks information for AD and the other picks for Access Control. I think this is arising due to naming conventions being slightly different in both indexes.

Is there a way we can tell Splunk that person Apple Banana is the same person as Apple Cabbage because "Apple" is the common thing in both indexes? And also have this result in one row instead of two?

0 Karma


If Apple is in the same field in both indexes, you can use that field in the by clause of a stats command - if not, copy it to a common field name

index=index1 OR index=index2
| eval apple_field=coalesce(apple_field1, apple_field2)
| stats values(*) as * by apple_field
0 Karma


The first steps are to ensure the access control system logs card swipes to Splunk and that logins to the domain also are logged in Splunk.

You may need to normalize the two since they may not use the same identifier.  That can be done in the search or by adding FIELDALIAS properties to the respective sourcetypes.

Then it's just a matter of searching for domain logins that don't have a corresponding card swipe.  This assumes there's no VPN or other means for accessing the domain without an access card.


index=domain_logins NOT [ search index=access_control | fields user | format ]


If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...

.conf23 Registration is Now Open!

Time to toss the .conf-etti 🎉 —  .conf23 registration is open!   Join us in Las Vegas July 17-20 for ...