Splunk User Behavior Analytics

analysing/visualising one to many relationships

tmtcollins
Explorer

Hi, I need to do some analysis on access permissions of an application.

I want to graphically show the relationships of users and the access they have. I have a simple data set like the format below (I have a much bigger dataset):

I would like to answer the question:

Of the users who have access to a specific folder, say "Apple", what other folders to they have access to and what are the associated volumes with that connection.

I was thinking Sankey diagram but I am having trouble getting the data in the right format. Any help would be really appreciated.

UserIDFolder
1Apple
1Banana
2Apple
3Apple
3Orange
Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...