Visits still open

Shown within a minute, scored carefully: eight rules wait for the end and nobody is cleared early.

Loghound writes a visit to the panel while it is still going on, so traffic shows up within about a minute instead of after the visit ends. A visit that is still open is scored more carefully, because some rules would accuse a person who simply has not finished yet.

A visit ends after 30 minutes with no request (the default). Until then its record is marked provisional and rewritten whenever it has new requests; the scorer runs once a minute. When the visit ends, the final record replaces it under the same id, and daily totals never count a provisional record.

01 · Eight rules wait for the visit to end
RuleWhy it waits
No JS on HTMLThe beacon reports when the page is hidden; a visitor still reading has not sent it.
No sub-resourcesThe stylesheet and image lines may not be written yet.
No conditional requestsNothing has been fetched twice yet.
No interactionThe visitor has not scrolled or clicked yet.
Single page, under 10sAt second one, every visit is one page under ten seconds.
Refused probe sweepA stylesheet or a real page may still follow the refused request.
Never served anythingThe next request may well be answered.
Mostly refusedThe share is still being counted over a growing visit.
02 · Held at unknown, never cleared early
  • An open visit can be called likely bot or bot at once on evidence already there: an automation marker, a client that is not a browser or a refused attack is named on the first request.
  • It cannot be called human or likely human while open, because “nothing against it yet” is not proof. It shows unknown with the reason Session still open.
  • Exception: a visitor already shown to be a person. With the beacon, that is 30 seconds of engaged time and at least one interaction. Without it (for example behind an ad blocker), 30 seconds of requests plus client hints that agree with the User-Agent or fetched page resources.
03 · Visits measured by the beacon alone

A visit to a site on another server has no access log behind it, so the twelve rules that read the request log are switched off for it: User-Agent rotation, no JS on HTML, no sub-resources, no conditional requests, single page under 10s, periodic timing, exploit probe, refused probe sweep, refused attack, got a 403, never served anything and mostly refused. The visit carries the reason One plane only.

Scoring

Loghound is open source and MIT licensed. Questions about the Opensolr half — the account, the indexes, the plan — go to opensolr.com/contact; questions about the software itself belong on GitHub.

Loghound Documentation