Splunk User Behavior Analytics

analysing/visualising one to many relationships

tmtcollins
Explorer

Hi, I need to do some analysis on access permissions of an application.

I want to graphically show the relationships of users and the access they have. I have a simple data set like the format below (I have a much bigger dataset):

I would like to answer the question:

Of the users who have access to a specific folder, say "Apple", what other folders to they have access to and what are the associated volumes with that connection.

I was thinking Sankey diagram but I am having trouble getting the data in the right format. Any help would be really appreciated.

UserIDFolder
1Apple
1Banana
2Apple
3Apple
3Orange
Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...

Splunkbase | Splunk Dashboard Examples App for SimpleXML End of Life

The Splunk Dashboard Examples App for SimpleXML will reach end of support on Dec 19, 2024, after which no new ...

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...