Application mapping provides a visual representation of the events that take place in your system based on the specific filter criteria.
You can drill down and view events on these levels:
Database — Events are aggregated by database (default level).
Source IP — Events are aggregated by source IP address for the selected database.
User ID address — Events are aggregated by user ID for the selected source IP address.
Command type — Events are aggregated by command type for the selected user ID.
The number of events that link each level is indicated on the lines (edges) that connect them.
From the navigation pane, select .