| OID symbolic | OID numeric | Type | Access | Description |
| cidsAlert | 1.3.6.1.4.1.9.9.383.1.2 | | | |
| U32 cidsAlertAlarmTraits | 1.3.6.1.4.1.9.9.383.1.2.2 | Unsigned32 | accessible-for-notify | The alarm traits is an unsigned 16-bit integer
representing the value of the 16 user-defined
alarm traits specified in the configuration for
the signature that triggered the alert. The
alarmTraits bits are used to classify signatures
into user-defined categories or groups. |
| STR cidsAlertAttackerAddress | 1.3.6.1.4.1.9.9.383.1.2.16 | SnmpAdminString | accessible-for-notify | Optional ip address and ports on a monitored
interface. The 'locality' attribute is a string
that indicates the relative location of the ip
address within the network mapping, such as whether
the address falls within the address range of a
protected network. The optional 'proxy' attribute
is 'true' if the sensor has reason to suspect that
the address given is not the address of the true
attacker. This could be a the result of address
spoofing or because the host has been compromised
and is acting as a 'zombie'. The 'proxy' attribute
may be omitted if and only if its value is false. |
| STR cidsAlertAttackerContext | 1.3.6.1.4.1.9.9.383.1.2.15 | SnmpAdminString | accessible-for-notify | Optional Base64-encoded representation of the stream
data that was sourced by the Attacker. |
| STR cidsAlertDetails | 1.3.6.1.4.1.9.9.383.1.2.21 | SnmpAdminString | accessible-for-notify | Optional. Textual details about the specific alert
instance, not just the signature. |
| U32 cidsAlertEventRiskRating | 1.3.6.1.4.1.9.9.383.1.2.25 | Unsigned32 | accessible-for-notify | A risk factor that incorporates several additional
pieces of information beyond the detection of a
potentially malicious action. The factors that
characterize this risk are the severity of the
attack if it were to succeed, the fidelity of the
signature, the relevance of the potential attack
with respect to the target host, and the overall
value of the target host to the customer. |
| I32 cidsAlertInterfaceGroup | 1.3.6.1.4.1.9.9.383.1.2.12 | Integer32 | accessible-for-notify | Optional numeric identifier for a sniffing
interface group on this host. |
| T/F cidsAlertIpLoggingActivated | 1.3.6.1.4.1.9.9.383.1.2.18 | TruthValue | accessible-for-notify | Optional. Indicates whether ip logging has been
activated as the result of the alert. A separate
evIpLogStatus event will be generated when logging
has been completed. The evIpLogStatus event contains
the URL where the log results may be obtained. This
element may be omitted if and only if its value
is false. |
| STR cidsAlertIpLogId | 1.3.6.1.4.1.9.9.383.1.2.22 | SnmpAdminString | accessible-for-notify | IP log identifiers for IP logs that were added as
the result of this alert. |
| STR cidsAlertSeverity | 1.3.6.1.4.1.9.9.383.1.2.1 | SnmpAdminString | accessible-for-notify | The severity associated with a Cids signature
(informational, low, medium or high for
example). |
| T/F cidsAlertShunRequested | 1.3.6.1.4.1.9.9.383.1.2.20 | TruthValue | accessible-for-notify | Optional. Indicates whether an ip address or tcp
connection has been requested to be shunned as a
result of the alert. Details about the addresses
and ports involved in the shun can be obtained from
evNacStatus events sent by the Network Access
Controller application. This element may be omitted
if and only if its value is false. |
| STR cidsAlertSignature | 1.3.6.1.4.1.9.9.383.1.2.3 | SnmpAdminString | accessible-for-notify | Content is a string containing details about the
signature that fired, without any specifics tied
to this instance of the alert. The
cidsAlertSignatureSigName, cidsAlertSignatureSigId
and cidsAlertSignatureSubSigId attributes define
the signature that triggered this Alert. |
| U32 cidsAlertSignatureSigId | 1.3.6.1.4.1.9.9.383.1.2.5 | Unsigned32 | accessible-for-notify | The ID of the Intrusion detection signature
that triggered this event. The ID combines
with the cidsAlertSignatureSubSigId to
create a unique key that identifies the
signature that generated this event. |
| STR cidsAlertSignatureSigName | 1.3.6.1.4.1.9.9.383.1.2.4 | SnmpAdminString | accessible-for-notify | The name of the Intrusion detection signature
that triggered this event. |
| U32 cidsAlertSignatureSubSigId | 1.3.6.1.4.1.9.9.383.1.2.6 | Unsigned32 | accessible-for-notify | The optional Sub ID of the Intrusion detection
signature that triggered this event. The Sub
ID combines with the cidsAlertSignatureSigId
to create a unique key that identifies the
signature that generated this event. |
| STR cidsAlertSignatureVersion | 1.3.6.1.4.1.9.9.383.1.2.7 | SnmpAdminString | accessible-for-notify | The optional version attribute defines the version
number of the signature update in which the triggering
signature was introduced or was last modified.
Example: 4.1(1.1)S47(0.1) |
| U32 cidsAlertSummary | 1.3.6.1.4.1.9.9.383.1.2.8 | Unsigned32 | accessible-for-notify | Optional, if present, specifies that this is a
summary alert, representing one or more alerts with
common characteristics. The numeric value indicates
the number of times the signature fired since the
last summary alert with a matching 'initialAlert'
attribute value. The first and all subsequent
summary alerts in a sequence will use the eventId
of a previous non-summary evAlert in the initialAlert
attribute value. All alerts represented by the
summary alert share the same signature and
sub-signature id. The summaryType attribute defines
the common characteristic(s) of all alerts in the
summary. The 'final' attribute indicates whether
this is the last evAlert containing the same value
in the 'initialAlert' attribute. The 'final'
attribute may be omitted if and only if its value
is false. |
| T/F cidsAlertSummaryFinal | 1.3.6.1.4.1.9.9.383.1.2.10 | TruthValue | accessible-for-notify | The optional 'final' attribute indicates whether
this is the last evAlert containing the same value
in the 'initialAlert' attribute. The 'final'
attribute may be omitted if and only if its value
is false. |
| UNS cidsAlertSummaryInitialAlert | 1.3.6.1.4.1.9.9.383.1.2.11 | Unsigned64 | accessible-for-notify | Serial number for the initial alert, which is
guaranteed unique within the scope of the
originating host. |
| STR cidsAlertSummaryType | 1.3.6.1.4.1.9.9.383.1.2.9 | SnmpAdminString | accessible-for-notify | Common characteristics shared by all non-summary
alerts included in a summary alert. |
| T/F cidsAlertTcpResetSent | 1.3.6.1.4.1.9.9.383.1.2.19 | TruthValue | accessible-for-notify | Optional. Indicates whether a attempt was made to
reset a tcp connection as the result of the alert.
The addresses and ports affected must be implied from
the information contained in the participant elements
of the evAlert. This element may be omitted if and
only if its value is false. |
| STR cidsAlertVictimAddress | 1.3.6.1.4.1.9.9.383.1.2.17 | SnmpAdminString | accessible-for-notify | Optional ip address and ports on a monitored
interface. The 'locality' attribute is a string
that indicates the relative location of the ip
address within the network mapping, such as
whether the address falls within the address range
of a protected network. |
| STR cidsAlertVictimContext | 1.3.6.1.4.1.9.9.383.1.2.14 | SnmpAdminString | accessible-for-notify | Optional Base64-encoded representation of the stream
data that was sourced by the victim. |
| U32 cidsAlertVlan | 1.3.6.1.4.1.9.9.383.1.2.13 | Unsigned32 | accessible-for-notify | An optional numeric identifier for a vlan. Identifies
the vlan that uses the number in ISL or 802.3.1q
headers. |
| cidsError | 1.3.6.1.4.1.9.9.383.1.3 | | | |
| STR cidsErrorMessage | 1.3.6.1.4.1.9.9.383.1.3.3 | SnmpAdminString | accessible-for-notify | A textual description of the error that occurred. |
| CID cidsErrorName | 1.3.6.1.4.1.9.9.383.1.3.2 | CidsErrorCode | accessible-for-notify | An enumerated error code, which identifies a general
class of errors. |
| STR cidsErrorSeverity | 1.3.6.1.4.1.9.9.383.1.3.1 | SnmpAdminString | accessible-for-notify | Severity of an error (warning, error or fatal
for example). An example of a type of error
that could occur would be when a requested
action could not be completed because it
would create a resource that would exceed a
system resource limit. |
| cidsGeneral | 1.3.6.1.4.1.9.9.383.1.1 | | | |
| UNS cidsGeneralEventId | 1.3.6.1.4.1.9.9.383.1.1.1 | Unsigned64 | accessible-for-notify | Identifies the sequence number of an event.
This value needs to be unique within the scope
of the originating host. |
| DAT cidsGeneralLocalTime | 1.3.6.1.4.1.9.9.383.1.1.2 | DateAndTime | accessible-for-notify | The local time on the Cisco intrusion detection
system sensor when the alert was generated. |
| STR cidsGeneralOriginatorAppId | 1.3.6.1.4.1.9.9.383.1.1.6 | SnmpAdminString | accessible-for-notify | The optional id of this instance of the application.
Typically the process id (pid). |
| STR cidsGeneralOriginatorAppName | 1.3.6.1.4.1.9.9.383.1.1.5 | SnmpAdminString | accessible-for-notify | The optional generic name of a Cids application. |
| STR cidsGeneralOriginatorHostId | 1.3.6.1.4.1.9.9.383.1.1.4 | SnmpAdminString | accessible-for-notify | A globally unique identifier for a Cids host. Could
be a host name or an ip address. |
| DAT cidsGeneralUTCTime | 1.3.6.1.4.1.9.9.383.1.1.3 | DateAndTime | accessible-for-notify | The UTC time on the Cisco intrusion detection
system sensor when the alert was generated. |
| cidsHealth | 1.3.6.1.4.1.9.9.383.1.4 | | | |
| G32 cidsHealthActiveNodes | 1.3.6.1.4.1.9.9.383.1.4.10 | Gauge32 | read-only | The number of active nodes currently queued in
the device. |
| C32 cidsHealthAlarmsGeneratedEx | 1.3.6.1.4.1.9.9.383.1.4.3 | Counter32 | read-only | The number of alarms generated, includes
all currently defined alarm severities. |
| STR cidsHealthCommandAndControlPort | 1.3.6.1.4.1.9.9.383.1.4.16 | SnmpAdminString | read-only | The status and network statistics of the
currently configured Command and Control
interface on the device. The Command
and Control interface is where all of the
communications for command and control
of the sensor occurs. This is important
to identify what interface a user will
communicate with to control the sensor
remotely and general health statistics
for that interface. |
| G32 cidsHealthDatagramsInFRU | 1.3.6.1.4.1.9.9.383.1.4.5 | Gauge32 | read-only | The number of datagrams currently queued in the
fragment reassembly unit. |
| G32 cidsHealthFragmentsInFRU | 1.3.6.1.4.1.9.9.383.1.4.4 | Gauge32 | read-only | The number of fragments currently queued in the
fragment reassembly unit. |
| G32 cidsHealthIpDualIp | 1.3.6.1.4.1.9.9.383.1.4.13 | Gauge32 | read-only | The number IP nodes keyed on both IP addresses
currently queued in the device. |
| T/F cidsHealthIsSensorActive | 1.3.6.1.4.1.9.9.383.1.4.15 | TruthValue | read-only | Indicates the failover status of the device.
True indicates the device is currently active.
False indicates it is in a standby mode. |
| U32 cidsHealthIsSensorMemoryCritical | 1.3.6.1.4.1.9.9.383.1.4.14 | Unsigned32 | read-only | A value between 0 and 10 that should rarely
get above 3. If this is non-zero the sensor
has stopped enforcing policy on some traffic in
order to keep up with the current traffic load;
the sensor is oversubscribed. The higher the
number the more oversubscribed the sensor. It
could be oversubscribed from a memory prospective
and not traffic speed. For example on a 200 Mbit
sensor this number might be 3 if the sensor was
only seeing 100Mbit of traffic but 6000
connections per second which is over the rated
capacity of the sensor. When the sensor is
in Memory Critical state then a ciscoCidsError
trap will be sent accordingly. |
| I32 cidsHealthPacketDenialRate | 1.3.6.1.4.1.9.9.383.1.4.2 | Integer32 | read-only | The percentage of packets denied due to
protocol and security violations. |
| I32 cidsHealthPacketLoss | 1.3.6.1.4.1.9.9.383.1.4.1 | Integer32 | read-only | The percentage of packets lost at the device
interface level. |
| TIK cidsHealthSensorStatsResetTime | 1.3.6.1.4.1.9.9.383.1.4.17 | TimeTicks | read-only | The value of SNMPv2-MIB::sysUpTime
when the Sensor specific statistics
was reset. The reset time is
collectively for the following objects:
cidsHealthPacketLoss,
cidsHealthPacketDenies,
cidsHealthAlarmsGenerated,
cidsHealthFragmentsInFRU,
cidsHealthDatagramsInFRU,
cidsHealthTcpEmbryonicStreams,
cidsHealthTcpEstablishedStreams,
cidsHealthTcpClosingStreams,
cidsHealthTcpStreams |
| G32 cidsHealthTcpClosingStreams | 1.3.6.1.4.1.9.9.383.1.4.8 | Gauge32 | read-only | The number of closing TCP streams currently
queued in the device. A stream will move
from the established state to closing when
a valid FIN or RST flag is received. |
| G32 cidsHealthTcpDualIpAndPorts | 1.3.6.1.4.1.9.9.383.1.4.11 | Gauge32 | read-only | The number TCP nodes keyed on both IP addresses
and both ports currently queued in the device. |
| G32 cidsHealthTcpEmbryonicStreams | 1.3.6.1.4.1.9.9.383.1.4.6 | Gauge32 | read-only | The number of embryonic TCP streams currently
queued in the device. TCP streams are
considered embryonic if they have not
completed the TCP three-way handshake. |
| G32 cidsHealthTCPEstablishedStreams | 1.3.6.1.4.1.9.9.383.1.4.7 | Gauge32 | read-only | The number of established TCP streams currently
queued in the device. Once a stream has
completed a TCP three-way handshake it will
move to the established state. |
| G32 cidsHealthTcpStreams | 1.3.6.1.4.1.9.9.383.1.4.9 | Gauge32 | read-only | The number of TCP streams (embryonic,
established and closing) currently queued
in the device. |
| G32 cidsHealthUdpDualIpAndPorts | 1.3.6.1.4.1.9.9.383.1.4.12 | Gauge32 | read-only | The number UDP nodes keyed on both IP addresses
and both ports currently queued in the device. |
| T/F cidsNotificationsEnabled | 1.3.6.1.4.1.9.9.383.1.1.7 | TruthValue | read-write | Indicates whether notifications will or will not
be sent when an event is generated by the device. |
| I32 cidsThreatResponseSeverity | 1.3.6.1.4.1.9.9.383.1.2.24 | Integer32 | accessible-for-notify | The alarm severity as assigned by the Cisco Systems
Threat Response engine. |
| STR cidsThreatResponseStatus | 1.3.6.1.4.1.9.9.383.1.2.23 | SnmpAdminString | accessible-for-notify | A brief textual description of the status of
the alarm given by the Cisco Systems Threat
Response engine. |
| NTF ciscoCidsAlert | 1.3.6.1.4.1.9.9.383.0.1 | | | Event indicating that some suspicious or malicious
activity has been detected on a monitored network. |
| ciscoCidsAlertObjectGroup | 1.3.6.1.4.1.9.9.383.2.2.2 | | | Alert Objects. |
| NTF ciscoCidsError | 1.3.6.1.4.1.9.9.383.0.2 | | | Event indicating that an error has occurred. |
| ciscoCidsErrorObjectGroup | 1.3.6.1.4.1.9.9.383.2.2.3 | | | Error Objects. |
| ciscoCidsGeneralObjectGroup | 1.3.6.1.4.1.9.9.383.2.2.1 | | | General Objects. |
| ciscoCidsHealthObjectGroup | 1.3.6.1.4.1.9.9.383.2.2.5 | | | Health Objects. |
| ciscoCidsMIB | 1.3.6.1.4.1.9.9.383 | | | Cisco Intrusion Detection System MIB. Provides
trap definitions for the evAlert and evError
elements of the IDIOM (Intrusion Detection and
Operations Messages) document and read support
for the Intrusion Detection System (sensor)
health information, such as if the sensor is
in a memory critical stage. |
| ciscoCidsMIBCompliance | 1.3.6.1.4.1.9.9.383.2.1.1 | | | The compliance statement for entities which implement
the Cids MIB |
| ciscoCidsMIBCompliances | 1.3.6.1.4.1.9.9.383.2.1 | | | |
| ciscoCidsMIBConform | 1.3.6.1.4.1.9.9.383.2 | | | |
| ciscoCidsMIBGroups | 1.3.6.1.4.1.9.9.383.2.2 | | | |
| ciscoCidsMIBNotifs | 1.3.6.1.4.1.9.9.383.0 | | | |
| ciscoCidsMIBObjects | 1.3.6.1.4.1.9.9.383.1 | | | |
| ciscoCidsNotificationsGroup | 1.3.6.1.4.1.9.9.383.2.2.4 | | | The notifications which are required. |