Understanding Network Honeypot Rulebase Notification Options
By default, logging is not enabled for Network Honeypot rulebase rules. You have the option to enable notification options. Table 1 describes these options.
Table 1: Network Honeypot Rulebase Notification Options
Option | Description |
|---|---|
Event logs and alerts | You can enable the following delivery and handling options for logs:
|
Packet captures | Viewing the packets used in an attack on your network can help you determine the extent of the attempted attack and its purpose, whether or not the attack was successful, and any possible damage to your network. If multiple rules with packet capture enabled match the same attack, IDP captures the maximum specified number of packets. For example, you configure rule 1 to capture 10 packets before and after the attack, and you configure rule 2 to capture 5 packets before and after the attack. If both rules match the same attack, IDP attempts to capture 10 packets before and after the attack. You can capture up to 256 packets before the event and 256 packets after the event. Note: If necessary, you can improve performance by logging only the packets received after the attack. |
![]() | Note: Network Honeypot rulebase notification options are the same as IDP rulebase options. |


