Exclude your own visits, filter known bots, and treat sudden spikes from unfamiliar sources with suspicion. On a small site this can be a substantial share of the total.

Why it matters more on a small site

Non-human traffic is roughly constant in absolute terms and proportionally enormous when the numbers are small.

A site with a hundred thousand sessions absorbs a few hundred bot visits without distortion.

A site with two hundred sessions does not. The same few hundred would double the figure.

Which means small business analytics is more vulnerable to this than any other category, and it is also the category least likely to have any filtering set up at all.

What is in there

The sixth is the largest single distortion on most small sites, and the easiest to remove.

Your own visits

An owner checking their site daily, a designer working on it for a week, and a member of staff looking up a price.

On a site with modest traffic that can be a noticeable fraction, and it is concentrated on exactly the pages you would want honest data about.

The usual fix is filtering by network address, which works for a fixed office connection and not for anybody working from several places.

A more reliable approach is a browser setting or extension that opts your own device out of analytics entirely, applied to every device in the business.

Either way it takes an afternoon once and improves every figure afterwards.

A worked example

A business whose analytics showed a consistent forty sessions a month to a single internal page nobody promoted.

The page turned out to be a staff-facing price list, linked from nowhere public and known to about four people.

It turned out to be two employees checking prices several times a day from their phones, plus an uptime monitoring service configured to load that page.

Once excluded, the site's total monthly sessions fell by about fifteen percent.

That was uncomfortable and it was the first honest figure they had ever had, and the trend from that point was interpretable.

The previous two years of data were not wrong so much as inflated by a constant that nobody had accounted for.

Referral spam

A specific nuisance worth recognising.

Fake visits appear in your report showing a referring domain, in the hope that you will visit it out of curiosity.

They never reached your site at all in some cases, and the entry exists purely to be read by you.

The signs are a domain you have never heard of, a suspiciously round number of sessions, a hundred percent bounce rate, and zero time on site.

Do not visit those domains. Filter them out and ignore them, since a visit from you is the entire purpose of the exercise.

Filtering after the fact

An important limitation worth knowing before setting anything up.

Most filters apply from the moment you create them and do not clean historical data.

Which means the two years of inflated figures stay inflated, and the series has a visible step at the point filtering began.

Some tools let you apply filters at reporting time instead, which does affect past data and is worth using where available.

Otherwise the practical response is to treat the filtering date as the start of a new series, and to avoid comparing across it.

Spikes that mean nothing

The pattern most likely to cause a wasted afternoon.

Traffic triples for a day, from an unfamiliar source or from a country you do not serve, and returns to normal.

That is almost never a marketing success and almost always a scraper, a scanner, or somebody's automated tool.

The tell is that those sessions have no depth at all: one page, no time recorded, no interaction, and frequently an unusual browser or a very old one.

Before celebrating or investigating any spike, check whether anything happened as a result. A spike with no enquiries and no engagement at all was not people.

The counter-case

Where the noise does not matter.

A business using analytics only to spot sudden breakage, where a constant background does not affect whether a drop is visible.

Any site where the enquiry count is the real measure and traffic is glanced at rather than relied on.

And situations where the effort of filtering exceeds the value, which is a fair judgement for a site with very little traffic and no decisions pending.

Even in those cases, excluding your own visits is worth the twenty minutes, because that single filter removes the largest and most misleading component of the total.

Server logs against script analytics

Worth understanding because the two disagree substantially and for a reason.

Script-based analytics only records visitors whose browser ran the script, which excludes most bots automatically and also excludes anybody blocking it.

Server logs record every request, which includes every bot, every scanner and every automated tool.

Which means logs overstate human traffic dramatically and analytics understates it modestly.

Neither is the truth, and comparing them is how people conclude their analytics is broken when both are working correctly.

For a small business, script analytics is the more useful of the two, precisely because its blind spot happens to filter out most of what you did not want to count.

How to tell if a session was a person

No single signal is conclusive and several together are reliable.

Sessions with zero seconds and one page view, in volume, from one source.

An improbable geographic pattern for a local business.

A browser or operating system nobody uses.

Perfectly regular timing, such as a visit every fifteen minutes, which indicates a monitor.

And no correlation with anything real: no enquiries, no phone taps, no repeat visits.

What to do

  1. Exclude your own devices, all of them.
  2. Turn on known bot filtering if your tool offers it.
  3. Identify your monitoring service and exclude it.
  4. Filter obvious referral spam as it appears.
  5. Note the date you started filtering, since earlier data is not comparable.
  6. Expect the numbers to fall, and do not treat that as a loss.

The fifth matters for interpretation later. A step change caused by filtering looks exactly like a collapse in traffic if nobody wrote down the date it happened.

Which numbers are worth watching once the data is clean is covered in sessions, users and why they disagree.


Frequently asked questions

Why does this matter more on a small site?

Non-human traffic is roughly constant in absolute terms. A few hundred bot visits are invisible on a large site and can double the total on a small one.

What is the biggest single distortion?

Your own visits, plus anybody else working on the site. It is also the easiest to remove and the most concentrated on pages you want honest data about.

How do I exclude myself?

Filtering by network address works for a fixed office. A browser setting or extension opting each device out is more reliable for anybody working from several places.

What is referral spam?

Fake visits showing an unfamiliar referring domain, existing purely so you will visit it. Filter them and do not visit, since that is the entire purpose.

Should I investigate a traffic spike?

Check whether anything resulted first. A spike with no enquiries, no engagement and one page per session was not people.

What happens when I start filtering?

The numbers fall, sometimes noticeably. Note the date, because a step change from filtering looks identical to a collapse in traffic.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Traffic figures that never seem to connect to anything?

Excluding your own devices is twenty minutes and removes the largest single distortion.

Start a Conversation