Splunk Search

Help please! - linkage analysis in Splunk

tmtcollins
Explorer

Hi, I hope someone can help guide me in what type of query or visualisation to use here so show the linkage of access permissions.

I have a simple data set like the format below (I have a much bigger dataset) It shows a user ID and the access they have to a folder.

Users can have access to more than one folder.

I would like to answer the question:

Of the users who have access to a specific folder, say "Apple", what other folders to they have access to and what are the associated volumes with that connection.

I was thinking Sankey diagram but I am having trouble getting the data in the right format.

UserIDFolder
1Apple
1Banana
2Apple
3Apple
3Orange
 
Many thanks, 
 
Tim
Labels (2)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...