Arpwatch messages currently report changes in Ethernet address, assuming that a host's IP address remains stable. In a network where the MAC remains stable and the IP address changes (eg. DHCP), it would be more useful to receive reports that use the MAC as the key and report changes in the associated IP address. This should be a runtime option.
Perhaps this could be useful, but only as an option, and not enabled by default! However, be prepared for a lot of noise if you have any virtual hosts on your net, where it's common and perfectly fine to have multiple IP addresses for a given MAC address. Also, depending on DHCP configuration, you may have a lot of changes in IP address for a given MAC address, which wouldn't necessarily be very interesting.
please report such things rfe's upstream...