How to Monitor and Analyze Traffic Patterns

Beginner 15 minutes DevOps / Security Engineers Dashboard & Analytics

Use the Traffic page to track package requests, filter by repository/client/outcome, identify anomalies, and understand your organization's dependency patterns.

Overview

The Traffic page is Chainsaw’s real-time activity log. Every package request that flows through the proxy is recorded with full context — package name, version, client, repository, outcome, and timestamp. This tutorial covers how to use the Traffic page to monitor activity, detect anomalies, and understand your organization’s dependency consumption patterns.

Prerequisites

  • Any role in Chainsaw (Member or above)
  • Traffic flowing through the proxy

Step 1: Navigate to the Traffic Page

Click Traffic in the sidebar. You’ll see a reverse-chronological feed of all package requests.

Traffic page showing activity feed
The Traffic page shows all package requests in real time

Step 2: Understand Traffic Entries

Each traffic entry contains:

FieldDescription
TimestampWhen the request occurred
RepositoryWhich registry was targeted (npmjs, pypi, etc.)
PackagePackage name
VersionRequested version
Client IDWhich credential made the request
Client TypeEnd User, Service Token, or AI Agent
OutcomeSuccess, blocked, flagged, or failed
CacheHit (served from cache) or miss (fetched upstream)
Detailed traffic entry
Each traffic entry shows complete request context

Step 3: Filter Traffic

By Repository

Focus on a specific ecosystem:

Filtering traffic by repository
Filter to see only npm, PyPI, or other ecosystem traffic

By Client

Track a specific team or pipeline:

Filtering traffic by client
Filter by client ID to see what a specific team is downloading

By Outcome

Focus on blocked or flagged requests:

Filtering traffic by outcome
Filter by outcome to see only blocked, flagged, or failed requests

By Date Range

Set a time window for your analysis:

Filtering traffic by date range
Set a date range to analyze specific periods
Combine filters to answer specific questions. For example: “Show me all blocked npm requests from the CI/CD service token in the last 24 hours.”

Step 4: Detect Anomalies

Watch for these patterns in the traffic feed:

Unusual Volume Spikes

A sudden increase in requests may indicate:

  • A new CI/CD pipeline being configured
  • A dependency update pulling many new packages
  • An automated attack (dependency confusion, mass scanning)
Traffic volume spike
A sudden spike in requests may warrant investigation

Unexpected Packages

Packages you don’t recognize in your ecosystem:

  • New transitive dependencies pulled in by an update
  • Typosquatted packages (similar to known packages)
  • Packages from unexpected ecosystems

Failed Requests

A cluster of failures may indicate:

  • Upstream registry outage
  • Misconfigured client credentials
  • Network connectivity issues
  • Package name typos in build configurations

Unusual Client Activity

A client credential that suddenly starts requesting packages from a new ecosystem or at unusual times.

Unusual client activity pattern
A service token that normally only uses npm suddenly requesting PyPI packages

Step 5: Analyze Dependency Patterns

Use traffic data to understand your organization’s dependency landscape:

Most Requested Packages

Identify your most critical dependencies — these deserve extra scrutiny:

Most frequently requested packages
Your most-requested packages are your highest-impact dependencies

Ecosystem Distribution

Understand which package managers dominate your traffic:

Traffic distribution by ecosystem
See which ecosystems account for the most traffic

Client Activity Comparison

Compare traffic volumes across teams and pipelines:

Traffic by client comparison
Compare package consumption across teams and CI/CD pipelines

Step 6: Investigate Blocked Requests

When a request is blocked, click on it to see:

  1. Which policy triggered the block
  2. Why — the specific condition that matched (CVSS score, license, etc.)
  3. Package details — version, ecosystem, metadata
  4. Client context — who requested it and from where
Blocked request investigation
Drill into blocked requests to understand why they were denied

Step 7: Use Billy for Traffic Analysis

Ask Billy to help analyze traffic patterns:

"What are the top 10 most downloaded packages this week?"
"Show me all failed requests in the last 24 hours"
"Which client has the highest request volume today?"
"Are there any packages being requested that we haven't seen before?"
Billy analyzing traffic patterns
Use Billy to query traffic patterns and identify trends

Step 8: Set Up Monitoring Workflows

Daily Check

  1. Open Traffic page
  2. Filter by outcome = blocked or flagged
  3. Review any new violations
  4. Check for anomalous patterns

Weekly Review

  1. Compare traffic volume to previous week
  2. Review top packages by request count
  3. Check cache hit ratio trends
  4. Identify new packages entering the supply chain

Incident Response

  1. Filter by the suspected time window
  2. Isolate the affected client or package
  3. Trace the request chain
  4. Cross-reference with audit logs

Next Steps