Splunk User Behavior Analytics

analysing/visualising one to many relationships

tmtcollins
Explorer

Hi, I need to do some analysis on access permissions of an application.

I want to graphically show the relationships of users and the access they have. I have a simple data set like the format below (I have a much bigger dataset):

I would like to answer the question:

Of the users who have access to a specific folder, say "Apple", what other folders to they have access to and what are the associated volumes with that connection.

I was thinking Sankey diagram but I am having trouble getting the data in the right format. Any help would be really appreciated.

UserIDFolder
1Apple
1Banana
2Apple
3Apple
3Orange
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...