Splunk user logon duration. I use the event_id 4624 (logon) and 4634(logoff).