---
title: Using Keystroke to User Behavior Analytics
slug: kronpam-reference-guide-3-5-0/using-keystroke-to-user-behavior-analytics
description: Learn how to analyze user behavior on the Kron PAM Login screen using Keystroke in this informative document. Find out how Keystroke is disabled for MFA users after a certain number of days and discover how a user's typing speed and accuracy are measured 
docTags: 
createdAt: 2023-04-26T09:32:20.000Z
---

Keystroke is used to understand the behavior of users on the Kron PAM Login screen and is used when only MFA is enabled for the User Group.

**Working Mechanism**

-  Keystroke will become disabled if MFA Users do not log in to the Login screen within a certain day. This number of days can be defined by parameter.
-  The user's Username and Password keyboard typing speeds and accuracy will be checked and measured with a threshold value. If the user does not exceed the threshold value, they will log in without the need for MFA


To enable Keystroke

1. Navigate t&#x6F;**&#x20;Administration > Multi-Factor Authentication > User Group Management.**
2. Click on the **Options** button.
3. Click th&#x65;**&#x20;Enable OTP** for User Group.
4. When the **Enable OTP&#x20;**&#x62;utton is clicked, the **Enable Keystroke** Button will become active.
5. Click th&#x65;**&#x20;Enable Keystroke&#x20;**&#x62;utton.

Keystrokes can be defined on the existing Kron PAM server or externally. For this, the following parameters must be defined in System Config Manager.

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/_37NhaqXXJ3U8gqG2y6GZ_image.png)

| **Parameter Name**                       | **Description**                                                                                                                      | **Sample Parameter Value**                                   |
| ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------ |
| keystroke.last.login.success.before.days | If the user doesn't have any MFA authentication login(login success with the token) last N days, keystroke prediction is not enabled | Default value: 15                                            |
| keystroke.api.url                        | Keystroke Server API URL                                                                                                             | [https://1.1.1.1:5000/predict](https://1.1.1.1:5000/predict) |
| keystroke.username.threshold             | Username prediction success threshold. The prediction distance must be under the threshold.                                          | Default value: 0.5                                           |

