Identifiers & labels

The panel shows words. The URL, the Solr document and the API carry identifiers. This is the mapping.

The panel speaks in words. The URL, the Solr document and anything you query yourself speak in identifiers. This page is the mapping, and it is the only place it exists.

Why both

An identifier is the right thing to store: it is stable, it is what a filter carries in a URL, it is what you grep a log for, and it is what a query you write yourself has to name. It is the wrong thing to show somebody who has never read the source. So the panel renders a label, and an identifier it does not recognise renders as itself — never as a wrong-but-plausible label, and never as blank.

01 · Signal codes

These are the values a session’s reasons field can hold. Seventeen are weighted rules; the last three carry no weight and are not accusations at all. The scoring page explains how they combine.

automation_marker

The page exposed a definitive driver artefact — the webdriver flag, a chromedriver global, Puppeteer, Playwright or Selenium hooks. Browsers do not have these; drivers do.

Label
Automation marker
Weight
100
Plane
execution
ua_declared_bot

It said it was a bot and it was telling the truth. Verdict bot, threat none.

Label
Declared crawler
Weight
100
Plane
transport
rdns_claim_failed

It declared itself a major crawler and forward-confirmed reverse DNS did not back that up. Impersonating a crawler is not a mistake anyone makes by accident.

Label
rDNS claim failed
Weight
95
Plane
transport
headless_renderer

WebGL reported SwiftShader, llvmpipe, Mesa OffScreen or Microsoft Basic Render: software rasterisation, which is what you get when there is no screen.

Label
Headless renderer
Weight
90
Plane
execution
beacon_forged

The claimed dwell time is impossible against the issue time of its own token. The lie is recorded rather than discarded, because the lie is the evidence.

Label
Forged beacon timing
Weight
90
Plane
execution
ua_claim_failed

The User-Agent claimed a browser version whose engine features the page does not actually have. A spoofed User-Agent string cannot retrofit a JavaScript engine.

Label
UA claim failed
Weight
85
Plane
execution
fp_cluster_proxy_fleet

Five or more distinct addresses shared this exact header fingerprint within twenty-four hours on non-mobile networks. One client, many exits.

Label
Proxy fleet fingerprint
Weight
80
Plane
behaviour
ua_secch_mismatch

A Chrome User-Agent arrived without the matching client hint, or with one that contradicts it. Chrome always sends its own client hints.

Label
Sec-CH-UA mismatch
Weight
75
Plane
transport
platform_mismatch

The platform client hint disagrees with the operating system the User-Agent claims.

Label
Platform mismatch
Weight
70
Plane
transport
no_js_on_html

An HTML page was served with a 200 and no beacon ever arrived, while the User-Agent claimed a real browser. Real browsers run scripts.

Label
No JS on HTML
Weight
70
Plane
behaviour
hosting_asn_browser_ua

A consumer browser User-Agent arriving from a hosting network. Weak alone — VPNs and corporate egress look like this — meaningful when stacked.

Label
Datacentre + browser UA
Weight
45
Plane
transport
periodic_timing

The gaps between requests are too regular across four or more requests. People are not metronomes.

Label
Periodic timing
Weight
45
Plane
behaviour
no_interaction

The beacon ran, the session ended, and not one scroll, click or key press ever happened.

Label
No interaction
Weight
40
Plane
execution
tz_mismatch

The browser timezone disagrees with the timezone of the address geolocation.

Label
Timezone mismatch
Weight
35
Plane
transport
no_304_on_repeat

The same assets were fetched again with no conditional header. A browser cache would have asked.

Label
No conditional requests
Weight
30
Plane
behaviour
no_assets

HTML was fetched and not a single stylesheet, script, font or image followed it.

Label
No sub-resources
Weight
25
Plane
behaviour
single_page_10s

One page, gone in under ten seconds. Very weak on its own; a bounce looks the same.

Label
Single page, under 10s
Weight
15
Plane
behaviour
provisional_session

The session had not ended when it was scored, so the five signals that can only be read after it ends were not evaluated and the verdict is held at unknown. Nothing was detected.

Label
Session still open
Weight
0
Plane
—
beacon_only_session

This site has no access log in this installation, so the session was measured by the beacon alone and the five signals that read the request log were not evaluated. Nothing was detected — but the evidence that remains is the plane a determined client controls, so treat the verdict as weaker than the same verdict on a session with a log behind it.

Label
One plane only
Weight
0
Plane
—
no_bot_signals

Every rule was evaluated and none of them fired. This is the absence of evidence, not evidence that a person was driving.

Label
Nothing fired
Weight
0
Plane
—
The reasons list is never empty

A session with nothing against it says so explicitly, so “no signals fired” and “the scorer did not run” are different states on the document rather than the same absence.

02 · Verdicts
human

Scored low enough that we believe a person drove this session.

Label
Human
likely_human

Some weak automation signals, not enough to call it a bot.

Label
Likely human
unknown

Scored, and the evidence did not reach a verdict either way. Not a failure to measure.

Label
Unknown
likely_bot

Enough signals to suspect automation, short of the bot threshold.

Label
Likely bot
bot

Automation, honest or not. Look at the class to tell which.

Label
Bot
03 · Bot classes
declared_crawler

Said what it was in the User-Agent and was telling the truth. Honest traffic.

Label
Declared crawler
ai_crawler

A declared crawler collecting for model training or inference.

Label
AI crawler
monitor

A declared uptime or availability checker.

Label
Monitor
spoofed_ua

The headers contradict each other, or a crawler claim failed reverse DNS.

Label
Spoofed User-Agent
proxy_fleet

One browser fingerprint arriving from many unrelated networks.

Label
Proxy fleet
headless

A driven or screenless browser: an automation marker, a software rasteriser, or a failed engine claim.

Label
Headless browser
scripted

Scored as automation without falling into any of the named classes.

Label
Scripted client
none

Not classed as a bot of any kind.

Label
Not automation
04 · Network types

Classified from the network operator’s name. These seven are the whole set: the classifier can only return one of the six named types or unknown. The hosting value is the one that matters most, because a consumer browser User-Agent arriving from hosting address space is a scoring signal in its own right.

hosting

Cloud, colocation, VPS or CDN address space. People do not browse from servers.

Label
Hosting / datacentre
isp

Residential or business broadband.

Label
Consumer ISP
mobile

Cellular address space, where many subscribers share few addresses. Excluded from the proxy fleet rule for exactly that reason.

Label
Mobile carrier
vpn

A commercial VPN, a private relay or a Tor exit.

Label
VPN / anonymiser
edu

A university, school or research network.

Label
Education
gov

A public-sector or military network.

Label
Government
unknown

The operator name did not match any known pattern.

Label
Unclassified
05 · Referrer types
direct

No referrer was sent: a bookmark, a typed address, or a client that strips it.

Label
Direct
internal

Referred from this site, or from a host configured as internal.

Label
Same site
ad

Carried an ad-network click id or a paid campaign medium. Tested before search, so a paid search click is never counted as organic.

Label
Paid ad
ai

Referred from an AI assistant or chat product.

Label
AI assistant
search

Organic: referred from a search engine with no paid click id.

Label
Search engine
social

Referred from a social platform.

Label
Social network
link

Referred from a site that is none of the above.

Label
Another site
06 · Declared bot categories
IdentifierLabelMeaning
searchSearch crawlerIndexes pages for a search engine.
aiAI crawlerCollects pages for model training or for answering in an assistant.
seoSEO toolA commercial backlink or audit crawler.
socialSocial previewFetches a page to build a link preview.
monitorUptime monitorChecks that the site is answering.
otherOther declared botDeclared itself a bot and does not fall into the named categories.
07 · Which planes a session was seen on
log_only

Seen in the web server log and never by the beacon: no script ran, or the visitor left before it reported.

Label
Server log only
log_beacon

Seen on both planes, so the log counts and the measured timings describe the same visit.

Label
Log and beacon
beacon_only

Reported by the beacon with no matching log line — a site on another server, or one whose log has not been read yet.

Label
Beacon only
The interesting value here is the absence

This field has no schema default, so every session indexed before it existed carries none of the three — and that absence means “this installation had not started recording which planes it had”, not “log only”. So the honest way to ask for sessions that have a transport plane is to exclude the beacon-only value, which keeps all of that history; asking for log-only instead would silently drop every older session and the count would look like a fact. The None of operator is what spells it, and the panel offers the remainder as its own row labelled “Not reported”.

The same three-state discipline applies to the signed-in dimension, whose two stored values are true (Signed in) and false (Anonymous), with absent meaning not reported — see identity.

08 · Fields with no vocabulary, deliberately

Dimensions that already hold words a person uses — a browser name, an operating system, a city, a network operator, a netname, a virtual host, a path, a TLS version — have no mapping at all. There is nothing to translate, and a half-populated map over real-world values would mean some rows got a label and some did not.

For the field names themselves and what each one is indexed, stored or faceted for, see the Solr schema.

Loghound is open source and MIT licensed. Questions about the Opensolr half — the account, the indexes, the plan — go to opensolr.com/contact; questions about the software itself belong on GitHub.

Loghound Documentation