Apm server configuration

Hi Team!

I understand apm server has to be private. I can place it behind a nginx load balancer. How do I ensure my apm server is secure. If I go to dev tools on my webpage, I can see the request to apm endpoint.

what is the right way to call apm endpoint and how to ensure its private?