I was looking to get some help in how to model a graph to track and analyse active directory events (logins to computers).
I have 2 main nodes (users and computers) both are loaded from data exported from active directory.
The next step would be to load the event data (timestamp, user, computer, success/error) and build a relationship between the user and the computer node. I was wondering if I should use a relationship with attributes or add an additional node for the event?
One thing to consider is that it the event data is a very large dataset to be loaded and queried.