All MIBs › TVD-MIB
Category: Network Management and SNMP Infrastructure
Description: Defines TVD device management objects for monitoring and configuration of TVD network equipment.
Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.
What Is TVD-MIB?
Despite its generic 'TVD' name, this module's actual content (module_desc and sample objects) shows it is a McAfee antivirus MIB used to report virus/malware detection events and engine status from McAfee endpoint or gateway security software via SNMP traps. It exposes fields describing detected threats: virus name and type, infected filename, affected username and OS, engine and DAT (signature) version, and the originating process/task. Its monitoring relevance is squarely software-status and security-event oriented: it lets an administrator track antivirus engine health (engine version, engine status) and signature currency (DAT version), as well as react immediately to virus detection events including which file, user, and host were involved. It has no apparent dependency on other standard MIBs, defining its own McAfee-specific trap OID tree. It is deployed wherever McAfee antivirus/endpoint security agents are installed and configured to send SNMP trap notifications to a central security console. Engineers can download the TVD-MIB file directly to load it into their MIB browser.
IPNetwork Monitor allows you to monitor SNMP objects defined in TVD-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.
Supported Devices
- McAfee antivirus/endpoint security software
- host running McAfee agent
Monitoring Examples
When a McAfee agent detects malware it sends a trap carrying mcafee_VIRUSNAME, mcafee_VIRUSTYPE, and mcafee_FILENAME identifying the threat and infected file, along with mcafee_USERNAME and mcafee_OS identifying the affected user and platform. An administrator monitoring mcafeeTVDTrap events can also check mcafee_ENGINEVERSION and mcafee_DATVERSION to confirm the detecting engine and signature set were current, and mcafee_NUMVIRS to see how many infections were found in that scan. mcafee_ENGINESTATUS reveals whether the antivirus engine itself is running normally or has failed.
What Can Be Monitored
- virus/malware detection events
- antivirus engine version and status
- signature (DAT) file version
- infected filename and affected user
- total virus count per scan
Imported Objects
From RFC-1212
| OBJECT-TYPE |
From RFC-1215
| TRAP-TYPE |
From RFC1155-SMI
| enterprises |
From RFC1213-MIB
| DisplayString |
OIDs
RFC description
McAfee Total Virus Defense MIB for antivirus event and trap management.
Start monitoring McAfee antivirus/endpoint security software, host running McAfee agent (virus-detection event/engine-version status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.