Find The: Time Since Last 
time_since_last
The time elapsed since the selected attribute(s) were last seen in an event, in other words the most recent interaction, in milliseconds for compatibility with the other time Features.
For example:
- Where authentication lasts for weeks or months, knowing how long the user has been logged in. The longer an authenticated session has been established, the greater the potential for an account takeover.
- Green-lighting users who have recently authenticated, and treating users logged in for weeks or months with greater scrutiny.
Configuration
- Feature Name: The "dictionary" name under which the feature value will be stored and referenced by in rules.
- For Events:
- With The Same: Provides a way of filtering past events based on the attribute values. There must be at least one Identifier and only Identifier and Subject attributes can be used.
Optional Configuration
- Default Value: A value that can be assigned to the feature if the attributes to calculate the features are not present.
- Scope: Can be used to extend the event search from the local node, to all nodes within the same organization all the way to all across customers (global).
- For Events:
- All event types: Default, no filter
- Same as current: Filter by event_type of event being processed
- Specific event type: List out the
event_typeto restrict to, as a list. Example: only consideraccount_login_success.
- Condition: A Query-Language filter that can be used to refine Features for specific use cases.
- Time Window: Can be used to limit the Feature calculation to a specific time period/window. e.g 1 week. Default is
all; no time window - Starting: Can be used to remove recent events from Feature calculation. Default is
immediately; no lag.
How Time Since Last is calculated
Configured for account_login_success events, it finds the most recent matching event and returns the time from there to this one. A more recent event of another type is skipped.

This event is itself the most recent match, so turning Include Current Event on returns 0 every time. Leave it off for a Time Since Last Feature.
Use Case 1
Identify if device logging into customer now last did so over a month ago
Using the Feature in Rules and Investigations
Device logging into account has logged in before but over a month ago. Time features return in milliseconds.
feature('dev_acc_session_age') > 1000 * 60 * 60 * 24 * 30
(time features return in milliseconds)
Implementing In The Feature Editor


- name: dev_acc_session_age
default_value: 0
time_window: all
starting: immediately
find_the:
time_since_last:
events:
event_type:
- account_login_success
include_current_event: false
with_the_same:
- device_signature['VER_1'].identifier
- identity['ACCOUNT'].customer_token.customer_token
with_scope: same_node_instance