CISCO-CIDS-MIB

        Cisco Intrusion Detection System MIB.  Provides
trap definitions for the evAlert and evError
elements of the IDIOM (Intrusion Detection and
Operations Messages) document and read support 
for the Intrusion Detection System (sensor) 
health information, such as if the sensor is
in a memory critical stage.
    
Source file
CISCO-CIDS-MIB
Last revised
Identity
ciscoCidsMIB
Base OID
1.3.6.1.4.1.9.9.383
Imported Objects
CISCO-SMI ciscoMgmt
CISCO-TC CiscoIpProtocol Unsigned64
IF-MIB InterfaceIndex
SNMP-FRAMEWORK-MIB SnmpAdminString
SNMPv2-CONF MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page)
SNMPv2-SMI Counter32 Gauge32 Integer32 MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-IDENTITY (no object page) OBJECT-TYPE (no object page) TimeTicks Unsigned32
SNMPv2-TC DateAndTime DisplayString TEXTUAL-CONVENTION (no object page) TruthValue
Net-SNMP examples using the cisco MIB directory Show commands

These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.

Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-CIDS-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-CIDS-MIB::ciscoCidsMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-CIDS-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-CIDS-MIB::ciscoCidsMIB'
How SNMP, Net-SNMP, MIB paths, and variants work
Objects (109)
.1.3.6.1.4.1.9.9.383
.1.3.6.1.4.1.9.9.383.0
.1.3.6.1.4.1.9.9.383.1
.1.3.6.1.4.1.9.9.383.1.1
.1.3.6.1.4.1.9.9.383.1.1.1
.1.3.6.1.4.1.9.9.383.1.1.2
.1.3.6.1.4.1.9.9.383.1.1.3
.1.3.6.1.4.1.9.9.383.1.1.4
.1.3.6.1.4.1.9.9.383.1.1.5
.1.3.6.1.4.1.9.9.383.1.1.6
.1.3.6.1.4.1.9.9.383.1.1.7
.1.3.6.1.4.1.9.9.383.1.2
.1.3.6.1.4.1.9.9.383.1.2.1
.1.3.6.1.4.1.9.9.383.1.2.10
.1.3.6.1.4.1.9.9.383.1.2.11
Integer32
.1.3.6.1.4.1.9.9.383.1.2.12
Unsigned32
.1.3.6.1.4.1.9.9.383.1.2.13
.1.3.6.1.4.1.9.9.383.1.2.14
.1.3.6.1.4.1.9.9.383.1.2.15
.1.3.6.1.4.1.9.9.383.1.2.16
.1.3.6.1.4.1.9.9.383.1.2.17
.1.3.6.1.4.1.9.9.383.1.2.18
.1.3.6.1.4.1.9.9.383.1.2.19
.1.3.6.1.4.1.9.9.383.1.2.2
.1.3.6.1.4.1.9.9.383.1.2.20
.1.3.6.1.4.1.9.9.383.1.2.21
.1.3.6.1.4.1.9.9.383.1.2.22
.1.3.6.1.4.1.9.9.383.1.2.23
Integer32
.1.3.6.1.4.1.9.9.383.1.2.24
.1.3.6.1.4.1.9.9.383.1.2.25
.1.3.6.1.4.1.9.9.383.1.2.26
.1.3.6.1.4.1.9.9.383.1.2.27
.1.3.6.1.4.1.9.9.383.1.2.28
.1.3.6.1.4.1.9.9.383.1.2.29
OctetString
.1.3.6.1.4.1.9.9.383.1.2.3
.1.3.6.1.4.1.9.9.383.1.2.30
.1.3.6.1.4.1.9.9.383.1.2.31
.1.3.6.1.4.1.9.9.383.1.2.32
.1.3.6.1.4.1.9.9.383.1.2.33
.1.3.6.1.4.1.9.9.383.1.2.34
.1.3.6.1.4.1.9.9.383.1.2.35
.1.3.6.1.4.1.9.9.383.1.2.36
.1.3.6.1.4.1.9.9.383.1.2.37
.1.3.6.1.4.1.9.9.383.1.2.38
.1.3.6.1.4.1.9.9.383.1.2.39
OctetString
.1.3.6.1.4.1.9.9.383.1.2.4
.1.3.6.1.4.1.9.9.383.1.2.40
.1.3.6.1.4.1.9.9.383.1.2.41
.1.3.6.1.4.1.9.9.383.1.2.42
.1.3.6.1.4.1.9.9.383.1.2.43
.1.3.6.1.4.1.9.9.383.1.2.44
.1.3.6.1.4.1.9.9.383.1.2.45
.1.3.6.1.4.1.9.9.383.1.2.46
.1.3.6.1.4.1.9.9.383.1.2.47
.1.3.6.1.4.1.9.9.383.1.2.48
OctetString
.1.3.6.1.4.1.9.9.383.1.2.49
.1.3.6.1.4.1.9.9.383.1.2.5
.1.3.6.1.4.1.9.9.383.1.2.6
OctetString
.1.3.6.1.4.1.9.9.383.1.2.7
.1.3.6.1.4.1.9.9.383.1.2.8
OctetString
.1.3.6.1.4.1.9.9.383.1.2.9
.1.3.6.1.4.1.9.9.383.1.3
.1.3.6.1.4.1.9.9.383.1.3.1
.1.3.6.1.4.1.9.9.383.1.3.2
.1.3.6.1.4.1.9.9.383.1.3.3
.1.3.6.1.4.1.9.9.383.1.4
percentInteger32
.1.3.6.1.4.1.9.9.383.1.4.1
.1.3.6.1.4.1.9.9.383.1.4.10
.1.3.6.1.4.1.9.9.383.1.4.11
.1.3.6.1.4.1.9.9.383.1.4.12
.1.3.6.1.4.1.9.9.383.1.4.13
Unsigned32
.1.3.6.1.4.1.9.9.383.1.4.14
.1.3.6.1.4.1.9.9.383.1.4.15
.1.3.6.1.4.1.9.9.383.1.4.16
.1.3.6.1.4.1.9.9.383.1.4.17
.1.3.6.1.4.1.9.9.383.1.4.18
.1.3.6.1.4.1.9.9.383.1.4.19
percentInteger32
.1.3.6.1.4.1.9.9.383.1.4.2
OctetString
.1.3.6.1.4.1.9.9.383.1.4.20
OctetString
.1.3.6.1.4.1.9.9.383.1.4.21
OctetString
.1.3.6.1.4.1.9.9.383.1.4.22
.1.3.6.1.4.1.9.9.383.1.4.23
.1.3.6.1.4.1.9.9.383.1.4.24
.1.3.6.1.4.1.9.9.383.1.4.25
.1.3.6.1.4.1.9.9.383.1.4.26
.1.3.6.1.4.1.9.9.383.1.4.27
OctetString
.1.3.6.1.4.1.9.9.383.1.4.28
percentInteger32
.1.3.6.1.4.1.9.9.383.1.4.29
.1.3.6.1.4.1.9.9.383.1.4.3
Integer32
.1.3.6.1.4.1.9.9.383.1.4.30
.1.3.6.1.4.1.9.9.383.1.4.31
.1.3.6.1.4.1.9.9.383.1.4.32
.1.3.6.1.4.1.9.9.383.1.4.32.1
OctetString
.1.3.6.1.4.1.9.9.383.1.4.32.1.1
.1.3.6.1.4.1.9.9.383.1.4.32.1.2
.1.3.6.1.4.1.9.9.383.1.4.33
.1.3.6.1.4.1.9.9.383.1.4.33.1
OctetString
.1.3.6.1.4.1.9.9.383.1.4.33.1.1
.1.3.6.1.4.1.9.9.383.1.4.33.1.2
.1.3.6.1.4.1.9.9.383.1.4.33.1.3
.1.3.6.1.4.1.9.9.383.1.4.4
.1.3.6.1.4.1.9.9.383.1.4.5
.1.3.6.1.4.1.9.9.383.1.4.6
.1.3.6.1.4.1.9.9.383.1.4.7
.1.3.6.1.4.1.9.9.383.1.4.8
.1.3.6.1.4.1.9.9.383.1.4.9
.1.3.6.1.4.1.9.9.383.2
.1.3.6.1.4.1.9.9.383.2.1
.1.3.6.1.4.1.9.9.383.2.2
Dependencies (9) 7 direct · 2 transitive Show tree and compile order Hide dependency details

Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.

Dependency tree
Dependency-first compile order
  1. SNMPv2-SMIrfc
  2. CISCO-SMIcisco
  3. SNMPv2-TCrfc
  4. CISCO-TCcisco
  5. IANAifType-MIBrfc
  6. SNMPv2-CONFrfc
  7. SNMPv2-MIBrfc
  8. IF-MIBrfc
  9. SNMP-FRAMEWORK-MIBrfc
  10. CISCO-CIDS-MIBciscoselected
Type Definitions (5)
Enumeration
notResponding(1)
notRunning(2)
processingTransaction(3)
reconfiguring(4)
running(5)
starting(6)
stopping(7)
unknown(8)
upgradeInprogress(9)
Enumeration
relevant(1)
notRelevant(2)
unknown(3)
Enumeration
errAuthenticationTokenExpired(1)
errConfigCollision(2)
errInUse(3)
errInvalidDocument(4)
errLimitExceeded(5)
errNotAvailable(6)
errNotFound(7)
errNotSupported(8)
errPermissionDenied(9)
errSyslog(10)
errSystemError(11)
errTransport(12)
errUnacceptableValue(13)
errUnclassified(14)
errWarning(15)
errEngineBuildFailed(16)
Enumeration
green(1)
yellow(2)
red(3)
Enumeration
zeroValue(1)
low(2)
medium(3)
high(4)
missionCritical(5)
Conformance Groups (14)
General Objects.
.1.3.6.1.4.1.9.9.383.2.2.1
Alert Objects.
.1.3.6.1.4.1.9.9.383.2.2.2
Error Objects.
.1.3.6.1.4.1.9.9.383.2.2.3
The notifications which are required.
.1.3.6.1.4.1.9.9.383.2.2.4
Health Objects.
.1.3.6.1.4.1.9.9.383.2.2.5
General Objects.
.1.3.6.1.4.1.9.9.383.2.2.6
Alert Objects.
.1.3.6.1.4.1.9.9.383.2.2.7
Optional Objects.
.1.3.6.1.4.1.9.9.383.2.2.8
Optional Objects.
.1.3.6.1.4.1.9.9.383.2.2.9
A collection of optional objects which provide sensor events
and alerts information.
.1.3.6.1.4.1.9.9.383.2.2.10
A collection of objects that provide sensor alert
information.
.1.3.6.1.4.1.9.9.383.2.2.11
A collection of objects that provide sensor health status.
.1.3.6.1.4.1.9.9.383.2.2.12
A collection of optional objects which provide sensor events
and alerts information.
.1.3.6.1.4.1.9.9.383.2.2.13
A collection of objects that provide sensor health and metric
change related trap information.
.1.3.6.1.4.1.9.9.383.2.2.14
Compliance Statements (5)

OID .1.3.6.1.4.1.9.9.383.2.1.1
The compliance statement for entities which implement
the Cids MIB
Required groups

OID .1.3.6.1.4.1.9.9.383.2.1.2
The compliance statement for entities which implement
the Cids MIB
Required groups
mandatory ciscoCidsGeneralObjectGroupRev1
mandatory ciscoCidsAlertObjectGroupRev1
mandatory ciscoCidsErrorObjectGroup
mandatory ciscoCidsHealthObjectGroup
mandatory ciscoCidsNotificationsGroup
optional ciscoCidsOptionalObjectGroup Since notifications with a large number of
bound objects can be rather large, the agent
can provide two different notification
generation modes. One without optional objects
in the ciscoCidsOptionalObjectGroup to try and
keep the notification size below 484 bytes and
one with no size limits that will send all
available optional objects in the
ciscoCidsOptionalObjectGroup as well as those
explicitly listed in the OBJECTS clause of the
notification definition.

OID .1.3.6.1.4.1.9.9.383.2.1.3
The compliance statement for entities which implement
the Cids MIB
Required groups
mandatory ciscoCidsGeneralObjectGroupRev1
mandatory ciscoCidsAlertObjectGroupRev1
mandatory ciscoCidsErrorObjectGroup
mandatory ciscoCidsHealthObjectGroup
mandatory ciscoCidsNotificationsGroup
optional ciscoCidsOptionalObjectGroupRev1 Since notifications with a large number of
bound objects can be rather large, the agent
can provide two different notification
generation modes. One without optional objects
in the ciscoCidsOptionalObjectGroup to try and
keep the notification size below 484 bytes and
one with no size limits that will send all
available optional objects in the
ciscoCidsOptionalObjectGroup as well as those
explicitly listed in the OBJECTS clause of the
notification definition.

OID .1.3.6.1.4.1.9.9.383.2.1.4
The compliance statement for entities which implement
the Cids MIB
Required groups
mandatory ciscoCidsGeneralObjectGroupRev1
mandatory ciscoCidsAlertObjectGroupRev1
mandatory ciscoCidsErrorObjectGroup
mandatory ciscoCidsHealthObjectGroup
mandatory ciscoCidsNotificationsGroup
optional ciscoCidsOptionalObjectGroupRev2 Since notifications with a large number of
bound objects can be rather large, the agent
can provide two different notification
generation modes. One without optional objects
in the ciscoCidsOptionalObjectGroup to try and
keep the notification size below 484 bytes and
one with no size limits that will send all
available optional objects in the
ciscoCidsOptionalObjectGroup as well as those
explicitly listed in the OBJECTS clause of the
notification definition.
optional ciscoCidsOptionalObjectGroupRev1 Since notifications with a large number of
bound objects can be rather large, the agent
can provide two different notification
generation modes. One without optional objects
in the ciscoCidsOptionalObjectGroup to try and
keep the notification size below 484 bytes and
one with no size limits that will send all
available optional objects in the
ciscoCidsOptionalObjectGroup as well as those
explicitly listed in the OBJECTS clause of the
notification definition.

OID .1.3.6.1.4.1.9.9.383.2.1.5
The compliance statement for entities which implement
the Cids MIB
Required groups
mandatory ciscoCidsErrorObjectGroup
mandatory ciscoCidsGeneralObjectGroupRev1
mandatory ciscoCidsAlertObjectGroupRev2
mandatory ciscoCidsHealthObjectGroupRev1
mandatory ciscoCidsNotificationsGroupRev1
mandatory ciscoCidsHealthObjectGroup
mandatory ciscoCidsNotificationsGroup
mandatory ciscoCidsAlertObjectGroupRev1
optional ciscoCidsOptionalObjectGroupRev3 A collection of optional objects which provide sensor events
and alerts information.
optional ciscoCidsOptionalObjectGroupRev2 A collection of optional objects which provide sensor events
and alerts information.
optional ciscoCidsOptionalObjectGroupRev1 A collection of optional objects which provide sensor alert
information.
Notifications / Traps (4)
NameOIDDescription
.1.3.6.1.4.1.9.9.383.0.1
Event indicating that some suspicious or malicious
activity has been detected on a monitored network.
.1.3.6.1.4.1.9.9.383.0.2
Event indicating that an error has occurred.
.1.3.6.1.4.1.9.9.383.0.3
This notification is triggered by the heart beat events
(evStatus). The heartbeat is configured to run on a periodic
basis and can be enabled/disabled through heart beat
configuration under the health service. If the heart beat is
disabled these notification events will not be sent.

This notification is supposed to mirror the heart beat evStatus
message however it is a subset of the most critical pieces of
data. Namely this will include the following pieces of data:

- Event ID
- Host ID
- Local Time
- UTC Time
- Overall Application Color
- Sensor/Inspection Load Color
- Overall Health
.1.3.6.1.4.1.9.9.383.0.4
This notification notifies the recipient of health and
security status changes. This notification is triggered when
there is a change in the value of monitored metrics as indicated
by evStatus message. This notification will include the
following important subset of attributes from evStatus message:

- Event ID
- Host ID
- Local Time
- UTC Time
- Overall Application Color
- Sensor/Inspection Load Color
- Overall Health

This is similar to the heart beat, however the triggering
condition is different. The heart beat fires on a regular
interval and this is sent immediately after a change in a
monitored metric. Metric change notifications can be enabled
while the heart beat is disabled.