2.11 Monitoring Module
The Monitoring module provides multi-dimensional observability across the Guardpot deployment, as shown in Figure 2.11-1.

Figure 2.11-1 β Monitoring Interface
2.11.1 Monitoring Dimensions
The module provides five analysis tabs for different monitoring perspectives, as shown in Figure 2.11.1-1.

Figure 2.11.1-1 β Monitoring Tab Navigation
Tab | Analysis Focus |
|---|---|
Agent | Honeypot agent health and operational status |
IP Address | Attacking IP address analysis with connection details |
Local Area | Internal network topology and activity analysis |
Interaction | Attacker interaction types (SSH, FTP, HTTP requests) |
Credential | Captured username/password combination analysis |
2.11.2 Agent Tab
The Agent tab provides health and operational status monitoring for honeypot agents, as shown in Figure 2.11.2-1.

Figure 2.11.2-1 β Agent Tab
This tab displays agent-level metrics once a Guardpot is selected and filters are applied via the Search button.
2.11.3 IP Address Tab
The IP Address tab enables analysis of connection data for specific attacker IP addresses, as shown in Figure 2.11.3-1.

Figure 2.11.3-1 β IP Address Tab
2.11.3.1 Filter Configuration
The following filters must be configured before analysis:
Filter | Description | Options |
|---|---|---|
IP Address * | Target IP address to analyze (required) | Enter an IP address |
Last Day Count * | Time range for analysis (required) | 1 Day, 7 Days, 14 Days, 30 Days, 90 Days |
2.11.3.2 Ready State
When filters are configured but search has not yet been initiated, the panel displays:
Ready to Search Enter an IP address to view connection analysis
Click the Search button to execute the analysis with the configured filters.
2.11.4 Local Area Tab
The Local Area tab visualizes internal network topology for selected Guardpot agents, as shown in Figure 2.11.4-1.

Figure 2.11.4-1 β Local Area Tab
2.11.4.1 Filter Configuration
Filter | Description |
|---|---|
Guardpot * | Select a honeypot agent to analyze (required) |
2.11.4.2 Ready State
When no agent has been selected, the panel displays:
Ready to Analyze Select agents to view local area network topology
Select a Guardpot from the dropdown and click Search to generate the network topology visualization.
2.11.5 Interaction Tab
The Interaction tab analyzes attacker interaction patterns and types, as shown in Figure 2.11.5-1.

Figure 2.11.5-1 β Interaction Tab
2.11.5.1 Filter Configuration
The tab displays an Attacker IP Addresses label with a text bar below containing the placeholder "Enter IP address". Enter a specific attacker IP to analyze their interaction history and types (SSH, FTP, HTTP requests, etc.).
Configure additional filters as needed and click Search to execute the analysis.
2.11.6 Credential Tab
The Credential tab checks whether specific passwords have been captured by honeypot agents, as shown in Figure 2.11.6-1.

Figure 2.11.6-1 β Credential Tab
2.11.6.1 Credential Check
The tab displays a Credential Check label with a text bar below containing the placeholder "Enter password". Enter a specific password string to check whether it has been captured in any credential-based attacks across the honeypot fleet.
Configure additional filters as needed and click Search to execute the analysis.
