# List the active users using login and logged out events

**URL:** <https://discuss.elastic.co/t/list-the-active-users-using-login-and-logged-out-events/96724>\
**Category:** Elasticsearch\
**Created:** [August 11, 2017, 8:18am UTC](https://discuss.elastic.co/t/list-the-active-users-using-login-and-logged-out-events/96724 "2017-08-11T08:18:24Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [August 11, 2017, 9:16am UTC](https://discuss.elastic.co/t/list-the-active-users-using-login-and-logged-out-events/96724/6 "2017-08-11T09:16:54Z")

</div>

> [@Hari17785](#):
>
> My approach may not be correct. Is there any other way or alternate solution to achieve this?

I can think of several:

1. Aggs solution - `terms` agg to group by session ID and sub aggs to gather related login/out events
2. Stream solution - use `scroll` api sorted on session ID
3. Active users index - create doc with session ID on login, delete on logout
4. [Entity-centric index](https://www.youtube.com/watch?v=yBf7oeJKH2Y) to track active sessions, durations and more.

Solution 1 is not scalable with large numbers of users and is needlessly bogged-down with historical inactive sessions.  
Solution 2 is scalable but slow and requires custom querying code  
Solution 3 requires custom indexing code but is easy to query  
Solution 4 requires custom scripts (examples available) but offers greater potential insights into sessions.

---

_[View the full topic](https://discuss.elastic.co/t/list-the-active-users-using-login-and-logged-out-events/96724)._
