Log File Analysis: Crawl Budget Optimization & Bot Behavior

Our company is engaged in the development, support and maintenance of sites of any complexity. From simple one-page sites to large-scale cluster systems built on micro services. Experience of developers is confirmed by certificates from vendors.

Development and maintenance of all types of websites:

Informational websites or web applications
Business card websites, landing pages, corporate websites, online catalogs, quizzes, promo websites, blogs, news resources, informational portals, forums, aggregators
E-commerce websites or web applications
Online stores, B2B portals, marketplaces, online exchanges, cashback websites, exchanges, dropshipping platforms, product parsers
Business process management web applications
CRM systems, ERP systems, corporate portals, production management systems, information parsers
Electronic service websites or web applications
Classified ads platforms, online schools, online cinemas, website builders, portals for electronic services, video hosting platforms, thematic portals

These are just some of the technical types of websites we work with, and each of them can have its own specific features and functionality, as well as be customized to meet the specific needs and goals of the client.

Showing 1 of 1All 2062 services
Log File Analysis: Crawl Budget Optimization & Bot Behavior
Medium
~2-3 days
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1358
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1251
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    957
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1188
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    929
  • image_bitrix-bitrix-24-1c_fixper_448_0.webp
    Website development for FIXPER company
    947

Web server logs are the only source of truth about search bot behavior. Unlike Google Search Console, which shows data with a delay, logs provide the real picture: which URLs Googlebot visits, how often, and with what errors. Based on this data, we optimize crawl budget. Over 5 years, we've analyzed logs of 200+ projects — typical savings of 40% unnecessary crawling. For example, on one project with 50,000 pages, Googlebot spent 80% of its budget on duplicates and technical pages that brought no traffic. After analysis, we reduced crawling by 35%, accelerating new article indexing by 2x. Server resource savings were substantial.

Why Log Analysis Is Indispensable for SEO?

Without logs, you work blind. Real problems solved by log file analysis:

  • Crawl budget diagnosis: Googlebot may waste 80% of resources on duplicates or low-value pages.
  • Identifying URLs that the bot visits but doesn't index (status 200, but absent from GSC).
  • Detecting slow-responding pages (response time > 3 s) — they slow down crawling.
  • Spotting unwanted bots (scrapers, aggressive parsers) that load the server.
  • Understanding infrastructure efficiency: if upstream_response_time increases, the backend is struggling.

How to Identify Search Bots?

Each bot has its own user-agent. Main ones:

CRAWLER_PATTERNS = {
    'Googlebot': r'Googlebot(?:/\d+\.\d+)?',
    'Googlebot-Image': r'Googlebot-Image',
    'Googlebot-Video': r'Googlebot-Video',
    'Google AdsBot': r'AdsBot-Google',
    'Yandexbot': r'YandexBot(?:/\d+\.\d+)?',
    'YandexImages': r'YandexImages',
    'Bingbot': r'bingbot(?:/\d+\.\d+)?',
    'Baiduspider': r'Baiduspider',
    'DuckDuckBot': r'DuckDuckBot',
}

def verify_googlebot(ip: str) -> bool:
    try:
        hostname = socket.gethostbyaddr(ip)[0]
        if not re.search(r'\.googlebot\.com$|\.google\.com$', hostname):
            return False
        resolved_ip = socket.gethostbyname(hostname)
        return resolved_ip == ip
    except socket.herror:
        return False

Googlebot authenticity is verified via reverse DNS. As noted in Googlebot verification, this is the only way to guarantee accuracy. We use a similar script and achieve 100% identification accuracy.

Parsing Logs: Basic Script

import re
import gzip
from pathlib import Path
from datetime import datetime
from collections import defaultdict, Counter
from dataclasses import dataclass, field
from typing import Iterator

LOG_PATTERN = re.compile(
    r'(?P<ip>[\d.]+) .+ \[(?P<time>[^\]]+)\] '
    r'"(?P<method>\w+) (?P<url>[^\s]+) HTTP/[\d.]+" '
    r'(?P<status>\d+) (?P<bytes>\d+) '
    r'"[^"]*" "(?P<ua>[^"]*)"'
    r'(?:\s+(?P<request_time>[\d.]+))?'
)

@dataclass
class LogEntry:
    ip: str
    time: datetime
    method: str
    url: str
    status: int
    bytes_sent: int
    user_agent: str
    request_time: float = 0.0
    crawler: str = ''

def parse_log_file(filepath: str) -> Iterator[LogEntry]:
    open_func = gzip.open if filepath.endswith('.gz') else open
    with open_func(filepath, 'rt', encoding='utf-8', errors='replace') as f:
        for line in f:
            m = LOG_PATTERN.match(line)
            if not m:
                continue
            try:
                entry = LogEntry(
                    ip=m.group('ip'),
                    time=datetime.strptime(m.group('time'), '%d/%b/%Y:%H:%M:%S %z'),
                    method=m.group('method'),
                    url=m.group('url'),
                    status=int(m.group('status')),
                    bytes_sent=int(m.group('bytes')),
                    user_agent=m.group('ua'),
                    request_time=float(m.group('request_time') or 0)
                )
                yield entry
            except (ValueError, AttributeError):
                continue

def identify_crawler(user_agent: str) -> str:
    for name, pattern in CRAWLER_PATTERNS.items():
        if re.search(pattern, user_agent, re.I):
            return name
    return ''

def analyze_crawler_behavior(log_files: list[str]) -> dict:
    crawler_stats = defaultdict(lambda: {
        'total_requests': 0,
        'urls': Counter(),
        'status_codes': Counter(),
        'slow_urls': [],
        'errors': [],
        'hourly_distribution': Counter()
    })

    for log_file in log_files:
        for entry in parse_log_file(log_file):
            crawler = identify_crawler(entry.user_agent)
            if not crawler:
                continue

            entry.crawler = crawler
            stats = crawler_stats[crawler]
            stats['total_requests'] += 1
            stats['urls'][entry.url] += 1
            stats['status_codes'][entry.status] += 1
            stats['hourly_distribution'][entry.time.hour] += 1

            if entry.request_time > 2.0:
                stats['slow_urls'].append({
                    'url': entry.url,
                    'time': entry.request_time,
                    'timestamp': entry.time.isoformat()
                })

            if entry.status >= 400:
                stats['errors'].append({
                    'url': entry.url,
                    'status': entry.status,
                    'timestamp': entry.time.isoformat()
                })

    return dict(crawler_stats)

Which Metrics Matter in Analysis?

After parsing, we look at these indicators:

Metric Normal Range Action on Anomaly
Crawl rate (requests/day) 100–5000 for average site Sharp drop — check robots.txt, server errors. Increase — content may be more popular.
Error rate 4xx/5xx <5% If >10% — fix broken links immediately, set up 301 redirects.
Average response time <1 s >2 s — optimize server, CDN, caching.
% duplicate crawling <20% Set canonical, block non-indexable sections in robots.txt.

If a bot often visits duplicate content sections — block them in robots.txt or add noindex.

How to Set Up Continuous Bot Monitoring?

For continuous monitoring, we stream logs to ClickHouse. ClickHouse processes data 10x faster than PostgreSQL, which is critical for volumes of 10M+ records.

CREATE TABLE crawler_logs (
    timestamp   DateTime,
    ip          IPv4,
    method      LowCardinality(String),
    url         String,
    status      UInt16,
    bytes       UInt32,
    user_agent  String,
    request_ms  Float32,
    crawler     LowCardinality(String)
) ENGINE = MergeTree()
PARTITION BY toYYYYMM(timestamp)
ORDER BY (crawler, timestamp)
TTL timestamp + INTERVAL 6 MONTH;

-- Query: top URLs that Googlebot visits but does not index (200 OK, absent from GSC)
SELECT url, count() as visits
FROM crawler_logs
WHERE crawler = 'Googlebot'
  AND status = 200
  AND timestamp >= now() - INTERVAL 30 DAY
GROUP BY url
ORDER BY visits DESC
LIMIT 50;

Typical pipeline: Filebeat → Logstash/Vector → ClickHouse. Output — Grafana dashboard with anomaly alerts. Setup stages:

Stage Tools Time
Log collection Filebeat, Vector 1 day
Parsing and loading Logstash, Vector → ClickHouse 2 days
Visualization Grafana 1 day
Alert configuration Grafana 1 day

What to Do with Parasitic Bots?

Not all bots are useful. We scan user_agent for unknown scrapers. Detected ones are blocked in nginx:

map $http_user_agent $bad_bot {
    default         0;
    ~*SemrushBot    0;
    ~*AhrefsBot     0;
    ~*MJ12bot       1;
    ~*DotBot        1;
}

server {
    if ($bad_bot) {
        return 403;
    }
}

What's Included in Our Log Analysis Service

We deliver a turnkey project:

  • Collect logs from servers (nginx, Apache, IIS) for the last 3–6 months.
  • Parse and clean: deduplication, filtering, enrichment with bot data.
  • Build a report with tables and charts: crawl rate, errors, slow pages.
  • Recommendations for optimization: fix errors, configure robots.txt, redirects.
  • Optional: set up an automated pipeline with ClickHouse + Grafana.
  • Transfer rights to scripts and dashboards.

Our engineers have 5+ years of experience, Google Analytics and Yandex.Metrica certifications. Data confidentiality is guaranteed.

Work Process: From Logs to Report

  1. Analysis — study current log structure and server configuration.
  2. Design — choose parsing method (Python, Go, or via ClickHouse).
  3. Implementation — write scripts, parse logs, export metrics.
  4. Testing — cross-check sample with GSC for data verification.
  5. Deployment — deliver the report, train your team on interpretation.

Timelines and Pricing

One-time analysis of one month (up to 5 GB) — 2–3 business days. Automated pipeline setup (parsing → ClickHouse → Grafana dashboard) with alerts — 4–7 days. Pricing is individual, based on log volume and infrastructure complexity. Get a consultation on your site's log analysis. We'll help uncover hidden indexing issues and save server resources. Contact us to estimate your project — we'll select the optimal stack and calculate timelines.

Why are Core Web Vitals critical for technical SEO?

PageSpeed 34/100 on mobile. Search Console shows red on all category pages. A competitor with an older site outranks you despite weaker content. Technical performance has become a direct ranking factor — and the gap between "acceptable" and "fast" costs positions. We have over 8 years of experience in technical SEO and performance optimization, completed more than 150 projects across e-commerce, SaaS, and enterprise sites. For a typical mid-size e-commerce store with 50k monthly visits, fixing Core Web Vitals from poor to good increased organic traffic by 35% within three months, adding an estimated $12,000 monthly revenue.

Core Web Vitals: what really affects rankings

Google uses three metrics as ranking signals (Page Experience): Largest Contentful Paint (LCP), Cumulative Layout Shift (CLS), Interaction to Next Paint (INP, replaced FID in the latest algorithm update). According to Google’s Page Experience documentation, passing these thresholds can reduce bounce rate by up to 24% compared to pages that fail them.

LCP: why 8 seconds is not an image problem

LCP measures rendering time of the largest visible element. Good <2.5s, poor >4s.

Real case: online clothing store, LCP 7.8s on mobile. Hero image 4.2MB JPEG without srcset, loaded via CSS background-image (not <img>). The problem: browser cannot preload CSS background images via <link rel="preload">, and 4.2MB on mobile connection is slow.

Solution:

  1. Move to <img> with fetchpriority="high" and loading="eager"
  2. Convert to WebP, add srcset: 800w for mobile, 1400w for desktop
  3. <link rel="preload" as="image" href="hero-800.webp" media="(max-width: 768px)"> in <head>
  4. Remove render-blocking scripts above hero with defer

Result: LCP 7.8s → 1.9s without changing hosting or CDN. That's 4x faster — a competitive advantage in search ranking.

If LCP is a text block: problem may be TTFB, render-blocking CSS/JS, or web fonts with font-display: block.

CLS: what causes layout shifts and how to stop them

CLS measures cumulative layout shift. Good <0.1, poor >0.25. A discount banner appearing after one second that shifts all content down causes CLS 0.35.

Sources:

  • Images without dimensions. <img src="photo.jpg"> without width/height — browser doesn't reserve space. Fix: explicit width/height or aspect-ratio in CSS.
  • Ad blocks and widgets — Google Ads, chat, cookie consent. Reserve space via min-height or load before main content.
  • Web fonts. font-display: swap with size-adjust minimizes CLS.
  • Dynamic content — add skeleton placeholder with dimensions.
Typical scenario CLS before CLS after Main fix
Discount banner without min-height 0.42 0.02 min-height: 300px
Article images without attributes 0.18 0.01 width/height + aspect-ratio
Chat widget loaded after 3s 0.35 0.05 position: fixed with reserved margin

INP: why interface freezes for 500ms

INP measures response delay to any user interaction. Good <200ms, poor >500ms. INP 680ms means user presses filter button and waits half a second.

Main cause: blocked main thread. A 2.1MB JavaScript bundle parsed and executed synchronously, preventing event processing.

Diagnosis: Chrome DevTools → Performance → interact → find Long Tasks (>50ms). Typical culprits:

  • Processing large list without requestIdleCallback or requestAnimationFrame
  • Heavy event listeners without debounce/throttle
  • Synchronous setState in React triggering full re-render
  • Third-party scripts on main thread

Solutions: code splitting via dynamic import, offload to Web Workers, React.memo + useMemo, Scheduler API.

How do structured data and Schema.org improve search visibility?

Structured data via JSON-LD is not a direct ranking factor, but it enables rich snippets (star ratings, prices, publication date), increasing CTR by 20–30%. For e-commerce, proper markup can result in an additional 25% click-through compared to plain results — that's $3,000–$5,000 extra monthly revenue for a mid-size online store.

Markup types by scenario:

  • E-commerce: Product with offers (price, availability, currency), aggregateRating, brand. BreadcrumbList, ItemList.
  • Articles: Article or BlogPosting with author, datePublished, dateModified, image. Organization and WebSite.
  • Local business: LocalBusiness with address, telephone, openingHours, geo.
  • FAQ: FAQPage with mainEntity — questions appear as expandable block.

Validation: Google Rich Results Test, Schema Markup Validator. Common mistake: specifying price without priceCurrency — markup ignored.

How to conduct a technical SEO audit

Crawlability. robots.txt blocks necessary pages or doesn't block service pages. Canonical URLs incorrectly set — duplicates with UTM parameters. Sitemap contains noindex pages. Tools like Screaming Frog or Sitebulb show this in an hour.

Core Web Vitals at scale. Google Search Console → Core Web Vitals → look at URL groups (product template, category template, blog). Problem is usually systemic.

JavaScript SEO. Google renders JS with delay. For critical content, SSR or SSG are mandatory. Check via Search Console → Inspect URL → View Crawled Page.

Internal linking. Orphan pages lose PageRank. Broken links (404) are a quality signal.

Common mistakes when implementing Schema.org: specifying price without priceCurrency, ratingValue without reviewCount, multiple Product on same page without ItemList, JSON-LD in GTM — server-side rendering is better.

What does the optimization process look like?

Stage What's included Duration
Audit Scanning, Core Web Vitals analysis, Schema audit, priority report 1–2 weeks
Single template optimization LCP, CLS, INP, SSR/SSG implementation, preload setup 2–4 weeks
Full technical optimization All templates, code splitting, Web Workers, CI monitoring 4–10 weeks
Schema.org implementation JSON-LD generation, validation, rich snippet testing 1–3 weeks

What deliverables do you receive?

  • Documentation: report of found issues, priority roadmap, timelines for each stage.
  • Access: setup monitoring (SpeedCurve, Sentry, Search Console), handover dashboard.
  • Training: one or two calls reviewing typical mistakes for your team.
  • Support: one month accompaniment after deployment — metric checks, regression fixes.

How many positions can you regain through technical SEO?

We have 5+ years on the market and 150+ projects completed. For a case study: a SaaS platform with 200k monthly visits had LCP 6.2s, CLS 0.45, INP 600ms. After optimization, LCP dropped to 1.8s, CLS to 0.02, INP to 180ms. Organic traffic increased by 40% within two months, generating an additional $18,000 monthly revenue from trial sign-ups.

Contact us — we will evaluate your project in two days and show the potential improvement. Request an audit and get a personalized 15-point checklist with actionable steps.