Yes, I agree there, but we are talking about investigating abnormal request times for small amount of users. Then logs are way to go. Just in the metrics you gather not only average, but also quantiles and generate some kind of histograms. Then you will notice enormous response times for that particular user while not polluting tags space with enormous amount of different values.