CISCO-CIDS-MIB

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-CIDS-MIB

Organization: Cisco Systems, Inc.

Last Updated: 2003-12-18

Category: Cisco Devices, Hardware and Environment

Description: Provides trap definitions for Cisco Intrusion Detection System (IDS) alert and error events, and read access to sensor health information such as memory-critical status.

IPNetwork Monitor uses several OIDs from this MIB in network discovery and polling the applicable devices. Start monitoring CISCO-CIDS-MIB with a free 30-day trial of IPNetwork Monitor.

What Is CISCO-CIDS-MIB?

CISCO-CIDS-MIB is a Cisco enterprise MIB for the Cisco Intrusion Detection System (IDS)/sensor product line, providing trap definitions that carry IDIOM (Intrusion Detection and Operations Messages) alert and error events, plus limited read-access objects for sensor health. It exposes alert metadata such as event ID, local/UTC timestamps, originating host and application identity, alert severity, alarm traits, and the specific attack signature name/ID that triggered an alert, alongside a notifications-enabled flag. Its monitoring focus includes both software/hardware sensor health and security event status: it explicitly supports reading whether the sensor has entered a memory-critical state, in addition to receiving traps for every detected intrusion alert or internal sensor error. It is layered on the IDIOM specification for intrusion event structure and is part of Cisco's broader security-appliance MIB family. It is typically deployed on Cisco IDS/IPS sensor appliances monitoring network traffic in enterprise or service-provider security operations centers. Network engineers evaluating or troubleshooting this functionality can download the CISCO-CIDS-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-CIDS-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Cisco IDS/IPS sensor appliance

Monitoring Examples

A SOC would subscribe to Cisco IDS traps carrying cidsAlertSeverity, cidsAlertAlarmTraits, and cidsAlertSignatureSigName/cidsAlertSignatureSigId to see which signature fired and how severe the detected attack was, correlating with cidsGeneralOriginatorHostId and cidsGeneralLocalTime/cidsGeneralUTCTime to pinpoint which sensor and when. An operator would separately poll the sensor's memory-critical health indicator to catch a sensor at risk of dropping alerts due to resource exhaustion before it stops detecting attacks. cidsNotificationsEnabled would be checked to confirm trap generation has not been inadvertently disabled on a sensor.

What Can Be Monitored

  • intrusion alert severity and signature
  • alert originating host/application
  • sensor memory-critical status
  • notifications-enabled state
  • alert/error event timestamps
Imported Objects

From CISCO-SMI

ciscoMgmtOBJECT-IDENTITY

From CISCO-TC

Unsigned64

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-CONF

MODULE-COMPLIANCE
NOTIFICATION-GROUP
OBJECT-GROUP

From SNMPv2-SMI

Counter32
Gauge32
Integer32
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE
TimeTicks
Unsigned32

From SNMPv2-TC

DateAndTime
TEXTUAL-CONVENTION
TruthValue

How to Use in IPNetwork Monitor

Example using cidsHealthAlarmsGenerated OID:

Select a Cisco IDS/IPS sensor appliance (legacy) as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type cidsHealthAlarmsGenerated into the Find box to locate it in the OID tree, then select it and click OK. The number of alarms generated, includes all currently defined alarm severities. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter32-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases sharply between polls relative to its normal baseline, since an unexpected spike often reflects a real change in traffic or activity. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

Monitors Cisco Intrusion Detection System (IDS) health, alerts, and error conditions for network threat detection.

Start monitoring Cisco IDS/IPS sensor appliance (legacy) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CISCO-CIDS-MIB