Lists the IP addresses of known attackers. An incident is created if an event is detected from one of these IP addresses. The IP Watch List table is a user configurable lookup table that is available for manually tracking known bad IP addresses. A separate internal IP Watch List is maintained via LiveUpdate and/or Symantec DeepSight updates, which contains a list of IP addresses that are known to be malicious in the larger Internet environment. Updates to this internal list do not affect the IP Watch List that is visible in the Information Manager Web configuration interface.