πŸ“„2. Guardpot Platform Administration

2.11 Monitoring Module

2 min read84 viewsUpdated May 20, 2026

The Monitoring module provides multi-dimensional observability across the Guardpot deployment, as shown in Figure 2.11-1.

Figure 2.11-1 – Monitoring Interface

Figure 2.11-1 – Monitoring Interface


2.11.1 Monitoring Dimensions

The module provides five analysis tabs for different monitoring perspectives, as shown in Figure 2.11.1-1.

Figure 2.11.1-1 – Monitoring Tab Navigation

Tab

Analysis Focus

Agent

Honeypot agent health and operational status

IP Address

Attacking IP address analysis with connection details

Local Area

Internal network topology and activity analysis

Interaction

Attacker interaction types (SSH, FTP, HTTP requests)

Credential

Captured username/password combination analysis


2.11.2 Agent Tab

The Agent tab provides health and operational status monitoring for honeypot agents, as shown in Figure 2.11.2-1.

Figure 2.11.2-1 – Agent Tab

This tab displays agent-level metrics once a Guardpot is selected and filters are applied via the Search button.


2.11.3 IP Address Tab

The IP Address tab enables analysis of connection data for specific attacker IP addresses, as shown in Figure 2.11.3-1.

Figure 2.11.3-1 – IP Address Tab

2.11.3.1 Filter Configuration

The following filters must be configured before analysis:

Filter

Description

Options

IP Address *

Target IP address to analyze (required)

Enter an IP address

Last Day Count *

Time range for analysis (required)

1 Day, 7 Days, 14 Days, 30 Days, 90 Days

2.11.3.2 Ready State

When filters are configured but search has not yet been initiated, the panel displays:

Ready to Search Enter an IP address to view connection analysis

Click the Search button to execute the analysis with the configured filters.


2.11.4 Local Area Tab

The Local Area tab visualizes internal network topology for selected Guardpot agents, as shown in Figure 2.11.4-1.

Figure 2.11.4-1 – Local Area Tab

2.11.4.1 Filter Configuration

Filter

Description

Guardpot *

Select a honeypot agent to analyze (required)

2.11.4.2 Ready State

When no agent has been selected, the panel displays:

Ready to Analyze Select agents to view local area network topology

Select a Guardpot from the dropdown and click Search to generate the network topology visualization.


2.11.5 Interaction Tab

The Interaction tab analyzes attacker interaction patterns and types, as shown in Figure 2.11.5-1.

Figure 2.11.5-1 – Interaction Tab

2.11.5.1 Filter Configuration

The tab displays an Attacker IP Addresses label with a text bar below containing the placeholder "Enter IP address". Enter a specific attacker IP to analyze their interaction history and types (SSH, FTP, HTTP requests, etc.).

Configure additional filters as needed and click Search to execute the analysis.


2.11.6 Credential Tab

The Credential tab checks whether specific passwords have been captured by honeypot agents, as shown in Figure 2.11.6-1.

Figure 2.11.6-1 – Credential Tab

2.11.6.1 Credential Check

The tab displays a Credential Check label with a text bar below containing the placeholder "Enter password". Enter a specific password string to check whether it has been captured in any credential-based attacks across the honeypot fleet.

Configure additional filters as needed and click Search to execute the analysis.

Was this article helpful?

Your feedback helps us improve our documentation.

Send feedback