It occurs to me that what you call a Bot is what the rest of us call an email filtering service that does malicious link checking and URL rewrite to provide time-of-click protection. They are the good guys, even if you find them inconvenient.
It sounds from the other comments that you may already have what you want, but any webhook is going to add latency that may be not significantly different than the delivery log buffering latency
It seems like the time-based approach may be over-engineering the problem. Click protection is in all the major products, so if you can identify the products, you should be able to separate the automated checks from the user clicks. There are a bunch of clues available to you:
- IIS Data: User agent, Reverse IP name, and Refer-From host, as Zack suggested
- DMARC Aggregate Report data: Reporting entity name and reporting domain name
- Delivery log data: MX DNS name, Helo name, and Reverse DNS name
I expect link checks will have a unique user agent and a host name that points to a major product, while the real clicks will have a refer-by name of the products server. Then this is validated by comparing to the other data sources.