HAVENGAI field note

What 2.5 Million Server Requests Taught Me About Who Visits a Small Business Website

On October 6, 2026, I pulled two weeks of web server logs for havengai.com — about 2.48 million request lines, September 22 through October 6 — and sorted the humans from the noise. If you run a small business website, what I found will change how you read your own traffic numbers.

What this gives you

01

What your dashboard hides

The gap between reported traffic and actual human visits on a real small-business site, measured line by line.

02

What the noise is made of

Crawlers, AI bots, your own systems polling themselves, and exploit scanners — named, sorted, and counted.

03

What a human looks like

Real visit patterns from the logs: direct entry, diligence reads, a voice greeting played five times out of curiosity.

04

What changes Monday

Pull your own raw logs, count the real audience, and put a tripwire on the page before the next human arrives.

01

Most of your “traffic” isn’t people

After stripping out four categories — search engine crawlers, AI crawlers, my own systems talking to themselves (the operator console, the command room, the live desk poll constantly), and exploit scanners probing for WordPress and phpMyAdmin holes — what remained was roughly 5 to 15 human-looking visits in two weeks.

Read that again. Millions of requests. Maybe a dozen people.

The rest is the background radiation of the internet: bots indexing, bots scraping, bots checking whether you’re running software they can break into. None of them will ever buy anything.

02

What the noise is made of

For the curious, here’s the composition of those 2.48 million lines across fourteen days of logs. The single largest category is my own infrastructure: the operator console, the command room, and the live desk poll their backends constantly — thousands of requests a day that look like traffic and mean nothing. Next come the crawlers: Google, Bing, and the AI crawlers, all explicitly allowed in my robots.txt. Then the background radiation: exploit scanners probing for WordPress admin pages, phpMyAdmin, exposed .git directories and .env files. On a typical day those probes number in the hundreds. They’ve never found anything because there’s nothing to find — but they never stop knocking.

What’s left after all of that — the 5 to 15 — is the real audience. Note the logs rotate daily, so this analysis stitched together fourteen daily files. Anyone doing this on their own site should expect the same shape: a mountain of machine noise with a handful of humans buried in it.

03

The few humans behaved like humans

They’re identifiable only by behavior, not by name — a server log shows IP addresses, not people. But a handful of visits read unmistakably human:

  • October 5: an iPhone typed havengai.com directly into the browser and read the homepage.
  • October 5: a Mac browsed the /authority/ page twice.
  • October 2: a Mac read the homepage, then opened the privacy page — the behavior of someone doing diligence.
  • October 2: an iPhone read the homepage, then the services page.
  • October 4: an iPhone read the homepage, then a guide page.

And one detail I like: somebody played Nova’s voice greeting — her first words as Arch — five times on October 6. A person, curious, hitting replay.

04

Zero of them left a trace

No questions submitted. No contact forms. No leads captured. Every one of those visitors arrived, looked around, and vanished back into the internet — and without the log analysis, I would never have known they existed at all.

That is the lesson, and it’s the whole reason tripwires exist. Traffic you can’t see might as well not have happened. A lead card on the page, a chat that answers, a form that takes thirty seconds — these aren’t marketing accessories. They’re the difference between “someone visited” and “someone visited and I know their name.”

05

What to do Monday morning

Pull your own server logs. Not the analytics dashboard — the raw logs. Filter out the bots (anything with “bot,” “crawl,” “spider” in its name), filter out your own office IP addresses, and look at what’s left. Whatever that number is, it’s your real audience. Then ask the uncomfortable question: if one of them wanted to reach you today, how many seconds would it take — and would you even know they tried?

Operator application

DIAGNOSE

Where does the evidence chain break?

Pull the raw access log, not the dashboard. Strip bots, your own IPs, and scanner probes. What remains is the real audience — count it honestly.

DECIDE

Which correction changes the position?

Put the capture mechanism on the highest-traffic page first. A tripwire on page forty of the sitemap catches no one.

RECEIPT

What proves the work moved?

A named lead in the inbox, not a hit counter. If the next human still leaves no trace, the tripwire isn’t working.

Next field note When Google’s AI Says “Never Heard of It” →

Your next move

See who your real visitors are.

Run the Position Scan

Direct answers

What serious buyers ask.

How do I pull my own server logs?

Ask your host for the raw access log. Filter user-agents containing “bot,” “crawl,” or “spider,” exclude your own office IP addresses, and read what’s left — that’s your real audience.

Are AI crawlers bad?

No — they’re how AI answers find you, and they’re explicitly allowed in HAVENGAI’s robots.txt. They just aren’t customers.

What is a tripwire?

Anything that turns an anonymous visit into a named contact: a lead card, a chat that answers, a form that takes thirty seconds. HAVENGAI pages carry a lead card that alerts the owner by email.

What does HAVENGAI charge for this kind of analysis?

The Position Scan starts free. The $495 Verified Position Brief goes the full distance, human-verified. Managed systems begin at $1,250 per month.