If a default action on a specific signature is configured to "produce alert" only, why is it that the IPS will also Log packet from the attacker? I would have thought that this would have required that the action "Log attacker packets" be selected as well.