What an entry can contain
| Field | How to interpret it |
|---|---|
| Time | When Bot Guard processed the event. Compare time zones when matching server, analytics, or provider logs. |
| IP address | The visitor address Bot Guard identified after applying trusted-proxy rules. |
| Requested page | The document or endpoint being evaluated. Static resources are normally excluded from strike creation. |
| Browser identification | The visitor’s claimed user-agent string; it can be missing, genuine, or intentionally spoofed. |
| Detection reason | The primary rule or condition associated with the event. |
| Signals and score | Supporting evidence from enabled request, navigation, protocol, timing, or browser checks. |
| Strike count | The active count after the event was handled. |
| Action | Allowed, observed, struck, blocked, or an action contributed by a premium module. |
Confirmed detection versus observation
An observation records context that is not strong enough to justify a strike by itself. A confirmed detection creates a strike. This distinction is important when reviewing browser validation, timing, fetch metadata, and other supporting signals.
Investigate an event
- Confirm the event is a document request and note the affected page.
- Read the primary reason and supporting signals together.
- Check whether the visitor identifies a known customer, employee, search crawler, monitor, CDN, or integration.
- Compare repeated entries for the same address and timing pattern.
- Decide whether to leave the strike, block, clear, or create a narrow trust rule.
Search, refresh, and clear
Refresh reloads recent events. Search narrows the displayed list by address or browser identification. Clear Logs removes the user-facing history; it does not clear active strikes or module statistics.
Storage and privacy
When Activity Logging is enabled, Bot Guard keeps up to 500 recent entries. Entries can contain personal data such as IP addresses and requested URLs, so access should remain limited to administrators and the site privacy notice should reflect the enabled logging.