We need more posts like this. I'd love a follow-up where instead of removing it injects fake data to the system. I am tired of passively being digitally assaulted. If they are going to do this to me without my knowing consent I want to fight back.
As a result, analytics endpoints generally have some authentication and verification built into them. Obviously, with enough time it's possible to reverse engineer these components. But that's a lot of time and effort vs just blocking the request.
Personally, I just plop it into a "dead letter office" table, then verify it's not malicious. But it's possible other companies would handle this differently.