Time Since Last

Prev Next

Find The: Time Since Last Image

time_since_last

The time elapsed since the selected attribute(s) were last seen in an event, in other words the most recent interaction, in milliseconds for compatibility with the other time Features.

For example:

  • Where authentication lasts for weeks or months, knowing how long the user has been logged in. The longer an authenticated session has been established, the greater the potential for an account takeover.
  • Green-lighting users who have recently authenticated, and treating users logged in for weeks or months with greater scrutiny.

Configuration

  • Feature Name: The "dictionary" name under which the feature value will be stored and referenced by in rules.
  • For Events:
    • With The Same: Provides a way of filtering past events based on the attribute values. There must be at least one Identifier and only Identifier and Subject attributes can be used.

Optional Configuration

  • Default Value: A value that can be assigned to the feature if the attributes to calculate the features are not present.
  • Scope: Can be used to extend the event search from the local node, to all nodes within the same organization all the way to all across customers (global).
  • For Events:
    • All event types: Default, no filter
    • Same as current: Filter by event_type of event being processed
    • Specific event type: List out the event_type to restrict to, as a list. Example: only consider account_login_success.
  • Condition: A Query-Language filter that can be used to refine Features for specific use cases.
  • Time Window: Can be used to limit the Feature calculation to a specific time period/window. e.g 1 week. Default is all ; no time window
  • Starting: Can be used to remove recent events from Feature calculation. Default is immediately ; no lag.

How Time Since Last is calculated
Configured for account_login_success events, it finds the most recent matching event and returns the time from there to this one. A more recent event of another type is skipped.

Time Since Last measures from the most recent matching event to this one

Include Current Event makes this 0

This event is itself the most recent match, so turning Include Current Event on returns 0 every time. Leave it off for a Time Since Last Feature.

Use Case 1

Identify if device logging into customer now last did so over a month ago

Using the Feature in Rules and Investigations

Device logging into account has logged in before but over a month ago. Time features return in milliseconds.

feature('dev_acc_session_age') > 1000 * 60 * 60 * 24 * 30

(time features return in milliseconds)

Implementing In The Feature Editor

image.png

image.png

  - name: dev_acc_session_age
    default_value: 0
    time_window: all
    starting: immediately
    find_the:
      time_since_last:
        events:
          event_type:
            - account_login_success
          include_current_event: false
          with_the_same:
            - device_signature['VER_1'].identifier
            - identity['ACCOUNT'].customer_token.customer_token
    with_scope: same_node_instance