Content Observability · User Analytics

The user experience your platforms actually deliver — observed, measured, proven.

Reveille User Analytics (RUA) is patented, passive real-user observability for Enterprise Content Management (ECM), Intelligent Document Processing (IDP), and automation applications. RUA observes the actual HTTP and HTTPS transactions your users generate — every login, retrieval, check-in, and API call — and turns them into response-time evidence, security insight, and adoption truth. It extends Reveille Metrics from what the platform reports to what your users experienced.

Monitor. Analyze. Connect.DashboardsUSER ANALYTICSOverviewUser ActivityResponse TimesApplication SecurityUser AdoptionSystem DashboardsReportsAdministrationLogsUser SettingsReveilleAboutFeedbackHelpUser AnalyticsTransaction Activity2,126 transactions · 24hVisuals ▾TRANSACTIONS2,126 · last 24hACTIVE USERS148 observedMEDIAN RESPONSE1.26 sFLAGGED1 suspicious loginTransaction counts by typeComposite2,12600:00nowLogin42400:00nowCheckOut42600:00nowCheckin42500:00nowDelete Document42600:00nowLogout42500:00now
The blind spot

The platform says it’s up. What did your users actually experience?

Monitoring tells you services are healthy and workflows are moving. It can’t tell you that a loan officer just waited nine seconds for a document, that a login pattern from a new location doesn’t look like your user, or which teams actually adopted the platform you paid for. Platform SLA is not workflow SLA — and neither is a user’s experience. Reveille User Analytics measures what really happened, transaction by transaction.

01

Availability ≠ experience

A platform can report healthy while users wait on every retrieval. Response-time pain lives in the client experience — between the browser or API call and the application — where platform-side monitoring never looks. So the first signal IT gets is a complaint.

02

Suspicious access hides in normal traffic

Insider misuse doesn’t trip an infrastructure alert — it looks like ordinary logins and document retrievals, just more of them, from somewhere new. Without a transaction-level record, the pattern is invisible until the damage is done.

03

Adoption is a guess without a record

License, training, and rollout decisions get made on anecdotes — who complained loudest, who showed up to training. Nobody can say who actually uses the platform, how often, or whether the investment landed.

Real user experience

See every transaction the way your users lived it

RUA maps raw HTTP/HTTPS packets into user-level transactions — so response-time conversations start from evidence, not anecdotes.

  • Continuously observe the actual HTTP/HTTPS user experience your platforms deliver — including encrypted (SSL) web and API-based applications
  • Rapidly identify user response-time service-level issues with response-time charts and application metric dashboards
  • Communicate user activity and business service-level information through dashboards, reports, and notification processes
Monitor. Analyze. Connect.DashboardsUSER ANALYTICSOverviewUser ActivityResponse TimesApplication SecurityUser AdoptionSystem DashboardsReportsAdministrationLogsUser AnalyticsResponse TimesSLA on targetVisuals ▾TRANSACTIONS33,118 · 7 daysAVERAGE2.3 sMEDIAN1.26 s90TH PERCENTILE5.97 sSystem response times · seconds0246SLA target ≤ 2s-7d-3dnowService-level attainmentAll transactions96.8% within SLA · 32,058 / 33,118Best 10% of transactions100.0% within SLA · 3,312 / 3,312Worst 10% of transactions82.4% within SLA · 2,729 / 3,312Objective record · actual user transactions
Security & insider visibility

Spot the access patterns that shouldn’t be there

Every content transaction RUA observes is also a security signal — who touched what, from where, how often.

  • Identify suspicious content access based on transaction frequency, user location, and content access activity
  • Security dashboards surface failed logins, suspicious logins, and document access by user and location
  • Application profiles control which transaction fields are kept or dropped for data-sensitivity compliance — and RUA never captures user passwords
Monitor. Analyze. Connect.DashboardsUSER ANALYTICSOverviewUser ActivityResponse TimesApplication SecurityUser AdoptionSystem DashboardsReportsAdministrationLogsUser AnalyticsApplication Security1 suspicious loginVisuals ▾Suspicious content access · jsmith28 logins · access frequency 14× baseline · new location 192.168.0.10 · flagged 09:12Failed loginsbkelly45jbenson42jsmith42madams41Suspicious loginsjsmith28 · frequency + locationDocuments by location192.168.0.1027192.168.0.99192.168.0.87192.168.0.76192.168.0.65192.168.0.54Transaction frequency · user location· content access activityDocument access count2,527readme.txt · top accessed · 24h-24hnowUnusual access spike · review in console
Adoption & accountability

Know who uses the platform — and prove it

User adoption dashboards and objective transaction history replace anecdotes with a record everyone can act on.

  • User adoption dashboards show who is using each application and how usage trends over a timeframe — backed by objective historical reporting on actual user transaction activity
  • Let a broad audience view and continually monitor your business-critical intelligent automation applications
  • Quickly observe and identify exceptions across the application user community
  • Coupled with the Reveille platform, deploy the proper resources to resolve detected problems — no more guessing which team owns the fix
Monitor. Analyze. Connect.DashboardsUSER ANALYTICSOverviewUser ActivityResponse TimesApplication SecurityUser AdoptionSystem DashboardsReportsAdministrationLogsUser AnalyticsUser Adoption148 active usersVisuals ▾ACTIVE USERS148 · 30 daysTRANSACTIONS33,118 observedEXCEPTIONS12 identifiedTREND▲ 18% vs prior 30dActive users · 30-day trend05010015030d ago15d agotodayMost active userswestes541bkelly531ledwards516bjones509hjohnson508Historical reportingObjective record of actual usertransaction activity · export · schedule
How RUA works

Four components. Zero interference.

RUA captures web application packets with licensed capture libraries on Windows, Linux, and AIX, parses them against application transaction profiles, and stores user-level transactions and protocol messages — then presents the results in the User Analytics Console and publishes them to Reveille Dashboards for a complete view of application and platform health.

YOUR USERSWeb & API clientsHTTP / HTTPS traffic01 · RUA COLLECTORPassive packet capturenpcap / pcap · span port, segment,app server, or Docker sidecar02 · REVEILLE SERVICEParse · profile · mapApplication transaction profilesturn packets into user transactions03 · RUA DATABASESQL Server / OracleMongoDB recommended forhigh-volume packet data04 · RUA CONSOLEDashboards & reportsPublishes to ReveilleDashboards for one viewmirrored, out-of-bandAES-256 · compressedencryptedFROM PACKET TO INSIGHT · NOTHING IN THE TRANSACTION PATHCapture reads network packets without interfering with packet information or routing — nothing sits in the transaction path,no user passwords are captured, and field-level controls govern what is stored.
Deploy it your way
Switch mirror/span port or hypervisor port mirroring (e.g., VMware’s virtual distributed switch), a network segment with application traffic access, the application server itself (Windows, Linux, AIX, or SUSE), or a Docker sidecar in Amazon EKS, Azure AKS, or RedHat OpenShift
Encrypted traffic
HTTP and HTTPS (SSL) monitored at the same time — RSA keys up to 4096-bit, TLS 1.2 cipher suites, decoded passively with your private key
Data stores
SQL Server or Oracle required; MongoDB recommended for high-volume packet data
Transport security
Collector-to-server packets compressed and 256-bit AES encrypted over a configurable, firewall-restricted port
Privacy by design
Never captures user passwords; field-level keep/drop controls for sensitive data; configurable retention and purge
Built for HA
RUA collectors support automatic failover to alternate Reveille servers running the Reveille HTTP Service
Managed remotely
The collector controller gives full, web-based remote control of RUA collectors on Windows and Linux
Watched by Reveille
A Reveille RUA monitor — via Reveille REST APIs — watches Reveille services, the collector, and packet and transaction activity

Application profiles are XML configuration files defining transactions, session timeouts, lookup tables, and field-level data-sensitivity rules. For customers on standard Reveille software maintenance, Reveille updates and recertifies profiles at no charge when your applications change.

Why Reveille

It only works if it always works.

User experience is where Service Level Assurance gets real. Platform SLA is not workflow SLA — Reveille User Analytics measures what your users actually received, and proves it.

Part of a broader platform

Real-user visibility across every platform you run

RUA application transaction profiles ship for every platform family Reveille observes — so real-user experience lands in the same console as platform health.

Questions

Reveille User Analytics, answered

What is Reveille User Analytics (RUA)?
Reveille User Analytics (RUA) is a patented application management solution for understanding the end-user experience, user activity, and user behavior of ECM, IDP, and automation applications. It passively captures HTTP and HTTPS application traffic, maps it into user-level transactions, and delivers response-time, security, and adoption insight through dashboards and reports — feeding the same Reveille platform that monitors, alerts, self-heals, and reports on your content stack.
How does RUA capture user activity?
RUA uses licensed packet capture libraries — npcap on Windows, pcap on Linux and AIX — to observe web application packets from a switch mirror/span port, hypervisor port mirroring, a network segment with application traffic access, the application server itself, or a Docker sidecar container. Captured packets are parsed against application transaction profiles and mapped into user-level transactions.
Does RUA slow down or interfere with my applications?
No. RUA is a passive network traffic collector: it reads packets without interfering with packet information or routing, and nothing sits inline in the transaction path. Collectors observe mirrored or local traffic out-of-band.
Can RUA see encrypted (HTTPS) traffic?
Yes. Provide the RSA private key used to encrypt the traffic and RUA decodes HTTPS alongside HTTP — both can be monitored at the same time. RUA supports RSA keys up to 4096-bit and TLS 1.2 RSA-based cipher suites. It deliberately does not support ephemeral Diffie–Hellman exchanges or TLS 1.3, because decoding those would require an active man-in-the-middle interceptor — which RUA, by design, is not.
Which platforms does RUA support?
RUA ships application transaction profiles for eight intelligent automation platform families: ABBYY, Box, Hyland, IBM, Microsoft, OpenText, Tungsten Automation, and UiPath. Reveille can modify profiles to support custom or modified web-based applications; the number of available profiles is controlled by Reveille licensing.
Does RUA capture passwords or sensitive data?
RUA never captures user passwords. Application profiles specify which transaction custom fields to keep or drop based on data sensitivity for security compliance, retention windows for transaction and packet data are configurable, and packets sent from collector to server can be encrypted with 256-bit AES over a configurable, firewall-restricted port.
Can RUA run in Kubernetes or containers?
Yes. The RUA HTTP and TCP collectors and the collector controller can run as sidecar containers alongside an application container in Amazon Elastic Kubernetes Service (EKS), Azure Kubernetes Service (AKS), and RedHat OpenShift (OCP). The Linux collector can be added to a Docker image or to an existing running container.
What does RUA require to run?
Four components: the RUA collector (Windows service or Linux/AIX process), the Reveille Service (a Windows-based 64-bit service), the web-based Reveille User Analytics Console, and the RUA database — SQL Server or Oracle, with MongoDB recommended for packet data in high-volume environments. The RUA server runs on 64-bit Windows Server.
What happens when a monitored application changes?
Application upgrades, virtual path changes, SSO changes, and cookie or header changes can alter transaction flow. For customers on standard Reveille software maintenance, Reveille reviews the changes, updates the application profile, and recertifies it at no charge — and recommends testing changes in a non-production environment first.
How does RUA work with the rest of the Reveille platform?
RUA publishes into Reveille Dashboards for one view of application and platform health, a Reveille RUA monitor uses Reveille REST APIs to watch collector, service, and transaction activity, and — coupled with Reveille monitoring and alerts — helps deploy the right resources to resolve detected problems accurately. RUA collectors also support automatic failover to alternate Reveille servers for high availability.
Get started

The content layer is where your business runs. Reveille makes sure it holds.

See RUA observing real user transactions on your platforms — response times, security signals, and adoption — in a live demo.