Hi there,
If you have activated the good level of logging from your cisco device you should have this event id 113019. In this log you have the complete duration of the VPN session + the username etc. The field is also call duration ...
index=myciscoindex Cisco_ASA_message_id=113019
2020-05-04T12:42:54+02:00 10.66.65.70 :May 04 10:41:42 UTC: %FTD-auth-4-113019: Group = RemoteAccessVPN-MUC, Username = xxx, IP = xxx.xxx.xxx.xxx, Session disconnected. Session Type: SSL, Duration: 2h:50m:01s, Bytes xmt: 21247692, Bytes rcv: 7087992, Reason: Idle Timeout
I mean you can also do transaction between the first IP assignment and this duration event to know the time but I think it's the best way to know the exact session time as this is directly the cisco device that give you that.
cheers
Vince
... View more