# Finding inactive users from event logs

**URL:** <https://discuss.elastic.co/t/finding-inactive-users-from-event-logs/48477>\
**Category:** Elasticsearch\
**Created:** [April 26, 2016, 8:58pm UTC](https://discuss.elastic.co/t/finding-inactive-users-from-event-logs/48477 "2016-04-26T20:58:02Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![elkcurious](https://avatars.discourse-cdn.com/v4/letter/e/858c86/32.png) [@elkcurious](https://discuss.elastic.co/u/elkcurious)\
**Post date:** [April 26, 2016, 8:58pm UTC](https://discuss.elastic.co/t/finding-inactive-users-from-event-logs/48477/1 "2016-04-26T20:58:02Z")

</div>

Hi,

If we store user-activity event logs in ES, is there a way to query for inactive users?

It is not clear ES allows me to query for "old" documents containing term "X", where there exists no recent documents with the same term "X".

I have seen a blog-post about creating "[entity-centic indices](https://www.elastic.co/elasticon/2015/sf/building-entity-centric-indexes)" to compute values like "average session duration" from login data events, as basic aggregations and pipelines are not sufficient. But, I would like to understand if a method exists without developing custom code required for the "entity-centric" index approach.

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:56pm UTC](https://discuss.elastic.co/t/finding-inactive-users-from-event-logs/48477/2 "2017-07-05T22:56:12Z")

</div>


