Find The: Time Since First 
time_since_first
The time elapsed since the selected attribute(s) were first seen in an event, in milliseconds for compatibility with the other time Features.
For example:
- Determining the "age" of a device or other attributes. An account, device and IP network range repeatedly seen together for three or more months is a positive indicator that the activity is legitimate.
- Performing step-up authentication when the age of a device is less than one day.
Configuration
- Feature Name: The "dictionary" name under which the feature value will be stored and referenced by in rules.
- For Events:
- With The Same: Provides a way of filtering past events based on the attribute values. There must be at least one Identifier and only Identifier and Subject attributes can be used.
Optional Configuration
- Default Value: A value that can be assigned to the feature if the attributes to calculate the features are not present.
- Scope: Can be used to extend the event search from the local node, to all nodes within the same organization all the way to all across customers (global).
- For Events:
- All event types: Default, no filter
- Same as current: Filter by event_type of event being processed
- Specific event type: List out the
event_typeto restrict to, as a list. Example: only consideraccount_login_success.
- Condition: A Query-Language filter that can be used to refine Features for specific use cases.
- Time Window: Can be used to limit the Feature calculation to a specific time period/window. e.g 1 week. Default is
all; no time window - Starting: Can be used to remove recent events from Feature calculation. Default is
immediately; no lag.
How Time Since First is calculated
Configured for account_login_success events with the same customer token and device identifier, it finds the oldest matching event and returns the time from there to this one. Events of other types are skipped, however recent they are.

Use Case 1
How long this customer has been logging in with this device. A device first seen on the account months ago is a positive indicator for a returning user; one first seen minutes ago, on an account that has existed for years, is worth a step-up challenge.
- With The Same pairs the customer token with the device identifier, so the age is of that combination and not of either on its own.
- The Default Value is 0, so the first login on a new device reads as an age of 0 rather than producing no Feature at all. That is the value a step-up rule tests.
Implementing In The Feature Editor


- name: cust_device_age
default_value: 0
time_window: all
starting: immediately
find_the:
time_since_first:
events:
event_type:
- account_login_success
include_current_event: false
with_the_same:
- identity['ACCOUNT'].customer_token.customer_token
- device_signature['VER_1'].identifier
with_scope: same_node_instance