Find The: Time Between 
time_between
Measures the time elapsed between events matching the configured criteria, in milliseconds, and calculates statistics across those spans. Useful for establishing a behavioural pattern for an account, user or device and comparing the current behaviour against it.
For example:
- Calculating the standard deviation of the time between account logins and comparing it with the time since the last login, to see how many standard deviations away the current gap is.
- Detecting bot or script attacks through bursts of events that are too fast to be human, or events occurring at precise regular intervals.
Configuration
- Feature Name: The "dictionary" name under which the feature value will be stored and referenced by in rules.
- For Events:
- With The Same: Provides a way of filtering past events based on the attribute values. There must be at least one Identifier and only Identifier and Subject attributes can be used.
- Into Features: Time Between can calculate multiple statistics from a single configuration and output them to the Feature Names given. Fill in the Feature Name for each statistic required and leave the rest blank. Every statistic you want needs its own Feature Name.
Optional Configuration
- Default Value: A value that can be assigned to the feature if the attributes to calculate the features are not present.
- Scope: Can be used to extend the event search from the local node, to all nodes within the same organization all the way to all across customers (global).
- For Events:
- All event types: Default, no filter
- Same as current: Filter by event_type of event being processed
- Specific event type: List out the
event_typeto restrict to, as a list. Example: only consideraccount_login_success.
- Condition: A Query-Language filter that can be used to refine Features for specific use cases.
- Time Window: Can be used to limit the Feature calculation to a specific time period/window. e.g 1 week. Default is
all; no time window - Starting: Can be used to remove recent events from Feature calculation. Default is
immediately; no lag.
How Time Between is calculated
Configured for account_login_success events with Include Current Event on, four logins produce three spans. Events that do not match are skipped, so a span runs from one matching event to the next and not to whatever happened in between.

Feature values are in milliseconds. For those logins: Average 1,800,000 (30 minutes), Minimum 1,200,000 (20 minutes), Maximum 2,400,000 (40 minutes) and Sum 5,400,000 (90 minutes, the whole stretch from the first login to this one).
Count returns the number of events, which is one more than the number of spans: three spans across four logins gives a Count of 4. Every other statistic is calculated over the spans.
Use Case 1
Bot or script attacks set to run at a precise interval, say every 10 seconds, can be detected using both the average and the standard deviation of the Time Between events. A real human is less precise and produces a higher standard deviation.
Compare the standard deviation with the average. If the standard deviation is below 10% of the average, the events are unusually evenly spaced, which is an indicator of a script or bot.
Implementing In The Feature Editor


