Quality
Bot traffic
Also called non-human traffic.
Bot traffic is hits generated by scripts, scrapers or other non-human clients. Some bots are welcome and many are not.
How it is measured
Spot them by user agent, request rate, missing JavaScript execution, data-centre IP ranges and impossible behaviour such as 40 pages in 10 seconds. Server logs show far more bots than client-side analytics, because many do not run scripts.
A script-based tracker like Tarsier only sees bots that execute JavaScript, such as headless browsers. Plain crawlers show up in your server logs, not in your pageviews.
Worked example
A small shop's page requests triple overnight from 300 to 920. The extra hits come from one data-centre range, request every product page in alphabetical order, and arrive 400 ms apart. Real sessions stay flat at 190.
The owner adds a rate limit at the edge and the next day returns to 310.
How it differs
Bot traffic is the broad family. A crawler fetches pages systematically. A spider is a crawler that follows links. Referrer spam is bot traffic aimed at your reports. Hit inflation is the effect on your numbers.
Common errors
Blocking all bots including search engines. Trusting user-agent strings. Leaving spikes unexplained. Looking only at analytics and not at logs. Assuming bots are always malicious.
In practice
Check a spike against your host or CDN logs before celebrating it. Block abusive ranges at the edge and leave search engines alone.