Home / Documentation / Activity Logs
TMB Bot Guard

Activity Logs

Interpret recent Bot Guard decisions and use the evidence to tune protection.

What an entry can contain

FieldHow to interpret it
TimeWhen Bot Guard processed the event. Compare time zones when matching server, analytics, or provider logs.
IP addressThe visitor address Bot Guard identified after applying trusted-proxy rules.
Requested pageThe document or endpoint being evaluated. Static resources are normally excluded from strike creation.
Browser identificationThe visitor’s claimed user-agent string; it can be missing, genuine, or intentionally spoofed.
Detection reasonThe primary rule or condition associated with the event.
Signals and scoreSupporting evidence from enabled request, navigation, protocol, timing, or browser checks.
Strike countThe active count after the event was handled.
ActionAllowed, observed, struck, blocked, or an action contributed by a premium module.

Confirmed detection versus observation

An observation records context that is not strong enough to justify a strike by itself. A confirmed detection creates a strike. This distinction is important when reviewing browser validation, timing, fetch metadata, and other supporting signals.

Investigate an event

  1. Confirm the event is a document request and note the affected page.
  2. Read the primary reason and supporting signals together.
  3. Check whether the visitor identifies a known customer, employee, search crawler, monitor, CDN, or integration.
  4. Compare repeated entries for the same address and timing pattern.
  5. Decide whether to leave the strike, block, clear, or create a narrow trust rule.

Search, refresh, and clear

Refresh reloads recent events. Search narrows the displayed list by address or browser identification. Clear Logs removes the user-facing history; it does not clear active strikes or module statistics.

Storage and privacy

When Activity Logging is enabled, Bot Guard keeps up to 500 recent entries. Entries can contain personal data such as IP addresses and requested URLs, so access should remain limited to administrators and the site privacy notice should reflect the enabled logging.