2.5 KiB
2.5 KiB
id, name, description, category, pages, status, version, triggers, owliver
| id | name | description | category | pages | status | version | triggers | owliver | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| activity-analysis | Activity Analysis | Break down what has happened in this workspace, by kind of event and by account. | operations |
|
active | 1 |
|
|
Activity Analysis
Purpose
- Report what has happened in this workspace and in what proportion.
- Count how many accounts are active.
- Show activity across recent periods.
Capabilities
- Break events down by kind, with each kind's share.
- Count distinct event kinds and active accounts.
- Window the breakdown by period.
Data
Reads activity.breakdown, which counts UserActivity records by event_type
and by account.
Analysis
Events are counted by kind and expressed as a share of the total, because a raw count means little without knowing whether twelve logins is most of the log or a fraction of it.
Stored event names are machine keys; they are rendered as words so a reader does
not have to translate hire_candidate in their head.
Output
Total events, number of distinct kinds, number of active accounts, then a row per kind with its count and share.
Limitations
- This describes the audit log, not the underlying records. Ten
apply_jobevents mean ten logged actions, which is not a guarantee of ten applications surviving in the pipeline. - Overlapping periods are deduplicated by event, so asking for today and the last seven days together does not double-count today.
- This counts activity; it does not judge it. Whether a pattern is unusual is Anomaly Detection's question.