If administration has configured SIP firewall rules with logs or alarms, all received SIP messages matching that rule will cause an alarm notification trap to be sent if the alarm option is set.
The log or alarm message includes the following information:
The action taken on the SIP message.
The matched rule name.
An administration-customized message.
The transport protocol over which the message was received.
Originating host address or port.
Destination host address or port.
For rules with track operation, the system displays the concrete track value. You can use these logging details to further analyze and mitigate threats to the system.