Splunk Search

Help please! - linkage analysis in Splunk

tmtcollins
Explorer

Hi, I hope someone can help guide me in what type of query or visualisation to use here so show the linkage of access permissions.

I have a simple data set like the format below (I have a much bigger dataset) It shows a user ID and the access they have to a folder.

Users can have access to more than one folder.

I would like to answer the question:

Of the users who have access to a specific folder, say "Apple", what other folders to they have access to and what are the associated volumes with that connection.

I was thinking Sankey diagram but I am having trouble getting the data in the right format.

UserIDFolder
1Apple
1Banana
2Apple
3Apple
3Orange
 
Many thanks, 
 
Tim
Labels (2)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...