Cisco Intrusion Detection System MIB. Provides trap definitions for the evAlert and evError elements of the IDIOM (Intrusion Detection and Operations Messages) document and read support for the Intrusion Detection System (sensor) health information, such as if the sensor is in a memory critical stage.
Unsigned64An unsigned 64 bit integer. We use SYNTAX Counter64 for the encoding rules. (0..18446744073709551615) · Counter64
Identifies the sequence number of an event. This value needs to be unique within the scope of the originating host.
cidsGeneralLocalTime
1.3.6.1.4.1.9.9.383.1.1.2
DateAndTimeA date-time specification.
field octets contents range
----- ------ -------- -----
1 1-2 year* 0..65536
2 3 month 1..12
3 4 day 1..31
4 5 hour 0..23
5 6 minutes 0..59
6 7 seconds 0..60
(use 60 for leap-second)
7 8 deci-seconds 0..9
8 9 direction from UTC '+' / '-'
9 10 hours from UTC* 0..13
10 11 minutes from UTC 0..59
* Notes: - the value of year is in network-byte order - daylight saving time in New Zealand is +13
For example, Tuesday May 26, 1992 at 1:30:15 PM EDT would be displayed as:
1992-5-26,13:30:15.0,-4:0
Note that if only local time is known, then timezone information (fields 8-10) is not present. SIZE (8 | 11) · OCTET STRING · hint 2d-1d-1d,1d:1d:1d.1d,1a1d:1d
The local time on the Cisco intrusion detection system sensor when the alert was generated.
cidsGeneralUTCTime
1.3.6.1.4.1.9.9.383.1.1.3
DateAndTimeA date-time specification.
field octets contents range
----- ------ -------- -----
1 1-2 year* 0..65536
2 3 month 1..12
3 4 day 1..31
4 5 hour 0..23
5 6 minutes 0..59
6 7 seconds 0..60
(use 60 for leap-second)
7 8 deci-seconds 0..9
8 9 direction from UTC '+' / '-'
9 10 hours from UTC* 0..13
10 11 minutes from UTC 0..59
* Notes: - the value of year is in network-byte order - daylight saving time in New Zealand is +13
For example, Tuesday May 26, 1992 at 1:30:15 PM EDT would be displayed as:
1992-5-26,13:30:15.0,-4:0
Note that if only local time is known, then timezone information (fields 8-10) is not present. SIZE (8 | 11) · OCTET STRING · hint 2d-1d-1d,1d:1d:1d.1d,1a1d:1d
The UTC time on the Cisco intrusion detection system sensor when the alert was generated.
cidsGeneralOriginatorHostId
1.3.6.1.4.1.9.9.383.1.1.4
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
A globally unique identifier for a Cids host. Could be a host name or an IP address.
cidsGeneralOriginatorAppName
1.3.6.1.4.1.9.9.383.1.1.5
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The optional generic name of a Cids application.
cidsGeneralOriginatorAppId
1.3.6.1.4.1.9.9.383.1.1.6
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The optional id of this instance of the application. Typically the process id (pid).
cidsNotificationsEnabled
1.3.6.1.4.1.9.9.383.1.1.7
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
Indicates whether notifications will or will not be sent when an event is generated by the device.
cidsAlertSeverity
1.3.6.1.4.1.9.9.383.1.2.1
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The severity associated with a Cids signature (informational, low, medium or high for example).
cidsAlertAlarmTraits
1.3.6.1.4.1.9.9.383.1.2.2
Unsigned32
The alarm traits is an unsigned 16-bit integer representing the value of the 16 user-defined alarm traits specified in the configuration for the signature that triggered the alert. The alarmTraits bits are used to classify signatures into user-defined categories or groups.
cidsAlertSignature
1.3.6.1.4.1.9.9.383.1.2.3
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (1..64) · OCTET STRING · hint 255t
Content is a string containing details about the signature that fired, without any specifics tied to this instance of the alert. The cidsAlertSignatureSigName, cidsAlertSignatureSigId and cidsAlertSignatureSubSigId attributes define the signature that triggered this Alert.
cidsAlertSignatureSigName
1.3.6.1.4.1.9.9.383.1.2.4
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (1..64) · OCTET STRING · hint 255t
The name of the Intrusion detection signature that triggered this event.
cidsAlertSignatureSigId
1.3.6.1.4.1.9.9.383.1.2.5
Unsigned32
The ID of the Intrusion detection signature that triggered this event. The ID combines with the cidsAlertSignatureSubSigId to create a unique key that identifies the signature that generated this event.
cidsAlertSignatureSubSigId
1.3.6.1.4.1.9.9.383.1.2.6
Unsigned32
The optional Sub ID of the Intrusion detection signature that triggered this event. The Sub ID combines with the cidsAlertSignatureSigId to create a unique key that identifies the signature that generated this event.
cidsAlertSignatureVersion
1.3.6.1.4.1.9.9.383.1.2.7
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (1..64) · OCTET STRING · hint 255t
The optional version attribute defines the version number of the signature update in which the triggering signature was introduced or was last modified. Example: 4.1(1.1)S47(0.1)
cidsAlertSummary
1.3.6.1.4.1.9.9.383.1.2.8
Unsigned32
Optional, if present, specifies that this is a summary alert, representing one or more alerts with common characteristics. The numeric value indicates the number of times the signature fired since the last summary alert with a matching 'initialAlert' attribute value. The first and all subsequent summary alerts in a sequence will use the eventId of a previous non-summary evAlert in the initialAlert attribute value. All alerts represented by the summary alert share the same signature and sub-signature id. The summaryType attribute defines the common characteristic(s) of all alerts in the summary. The 'final' attribute indicates whether this is the last evAlert containing the same value in the 'initialAlert' attribute. The 'final' attribute may be omitted if and only if its value is false.
cidsAlertSummaryType
1.3.6.1.4.1.9.9.383.1.2.9
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..16) · OCTET STRING · hint 255t
Common characteristics shared by all non-summary alerts included in a summary alert.
cidsAlertSummaryFinal
1.3.6.1.4.1.9.9.383.1.2.10
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
The optional 'final' attribute indicates whether this is the last evAlert containing the same value in the 'initialAlert' attribute. The 'final' attribute may be omitted if and only if its value is false.
cidsAlertSummaryInitialAlert
1.3.6.1.4.1.9.9.383.1.2.11
Unsigned64An unsigned 64 bit integer. We use SYNTAX Counter64 for the encoding rules. (0..18446744073709551615) · Counter64
Serial number for the initial alert, which is guaranteed unique within the scope of the originating host.
cidsAlertInterfaceGroup
1.3.6.1.4.1.9.9.383.1.2.12
Integer32
This object indicates an optional numeric identifier for a sniffing interface group on this host.
cidsAlertVlan
1.3.6.1.4.1.9.9.383.1.2.13
Unsigned32 (0..65535)
An optional numeric identifier for a vlan. Identifies the vlan that uses the number in ISL or 802.3.1q headers.
cidsAlertVictimContext
1.3.6.1.4.1.9.9.383.1.2.14
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
Optional Base64-encoded representation of the stream data that was sourced by the victim.
cidsAlertAttackerContext
1.3.6.1.4.1.9.9.383.1.2.15
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
Optional Base64-encoded representation of the stream data that was sourced by the Attacker.
cidsAlertAttackerAddress
1.3.6.1.4.1.9.9.383.1.2.16
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
Optional IP address and ports on a monitored interface. The 'locality' attribute is a string that indicates the relative location of the IP address within the network mapping, such as whether the address falls within the address range of a protected network. The optional 'proxy' attribute is 'true' if the sensor has reason to suspect that the address given is not the address of the true attacker. This could be a the result of address spoofing or because the host has been compromised and is acting as a 'zombie'. The 'proxy' attribute may be omitted if and only if its value is false.
cidsAlertVictimAddress
1.3.6.1.4.1.9.9.383.1.2.17
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
Optional IP address and ports on a monitored interface. The 'locality' attribute is a string that indicates the relative location of the IP address within the network mapping, such as whether the address falls within the address range of a protected network. The 'osIdSource' attribute represents the method that the operating system of the victim was identified. The 'osType' attribute represents the operating system of the target system. The 'osRelevance' attribute represents the relevance of an attack on the operating system.
cidsAlertIpLoggingActivated
1.3.6.1.4.1.9.9.383.1.2.18
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
Indicates whether IP logging has been activated as the result of the alert. A separate evIpLogStatus event will be generated when logging has been completed. The evIpLogStatus event contains the URL where the log results may be obtained. This element may be omitted if and only if its value is false.
cidsAlertTcpResetSent
1.3.6.1.4.1.9.9.383.1.2.19
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
Indicates whether a attempt was made to reset a tcp connection as the result of the alert. The addresses and ports affected must be implied from the information contained in the participant elements of the evAlert. This element may be omitted if and only if its value is false.
cidsAlertShunRequested
1.3.6.1.4.1.9.9.383.1.2.20
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
Indicates whether an IP address or tcp connection has been requested to be shunned as a result of the alert. Details about the addresses and ports involved in the shun can be obtained from evNacStatus events sent by the Network Access Controller application. This element may be omitted if and only if its value is false.
cidsAlertDetails
1.3.6.1.4.1.9.9.383.1.2.21
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
Textual details about the specific alert instance, not just the signature.
cidsAlertIpLogId
1.3.6.1.4.1.9.9.383.1.2.22
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
IP log identifiers for IP logs that were added as the result of this alert.
cidsThreatResponseStatus
1.3.6.1.4.1.9.9.383.1.2.23
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
A brief textual description of the status of the alarm given by the Cisco Systems Threat Response engine.
cidsThreatResponseSeverity
1.3.6.1.4.1.9.9.383.1.2.24
Integer32
The alarm severity as assigned by the Cisco Systems Threat Response engine.
cidsAlertEventRiskRating
1.3.6.1.4.1.9.9.383.1.2.25
Unsigned32
A risk factor that incorporates several additional pieces of information beyond the detection of a potentially malicious action. The factors that characterize this risk are the severity of the attack if it were to succeed, the fidelity of the signature, the relevance of the potential attack with respect to the target host, and the overall value of the target host to the customer.
cidsAlertIfIndex
1.3.6.1.4.1.9.9.383.1.2.26
InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d
The ifIndex on which the activity was detected.
cidsAlertProtocol
1.3.6.1.4.1.9.9.383.1.2.27
CiscoIpProtocolIP protocol number range.Reference: Internet Protocol. J. Postel. RFC791 (0..255) · Integer32
Identifies the IP protocol associated with the alert.
cidsAlertDeniedAttacker
1.3.6.1.4.1.9.9.383.1.2.28
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
Indicates that the traffic from originating from the attacker is being blocked as a result of the alert. This element may be omitted if and only if its value is false.
cidsAlertDeniedFlow
1.3.6.1.4.1.9.9.383.1.2.29
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
Indicates that the traffic on the TCP connection being blocked as a result of the alert. This element may be omitted if and only if its value is false.
cidsAlertDenyPacketReqNotPerf
1.3.6.1.4.1.9.9.383.1.2.30
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
Indicates whether the packet that triggered the alert would have been denied as a result of the alert if the intrusion prevention system was operating in inline mode. However, the packet was not actually denied because the intrusion prevention system was operating in promiscuous mode. This element may be omitted if and only if its value is false.
cidsAlertDenyFlowReqNotPerf
1.3.6.1.4.1.9.9.383.1.2.31
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
Indicates whether the flow that triggered the alert would have been denied as a result of the alert if the intrusion prevention system was operating in inline mode. However, this action was not actually taken because the intrusion prevention system was operating in promiscuous mode. This element may be omitted if and only if its value is false.
cidsAlertDenyAttackerReqNotPerf
1.3.6.1.4.1.9.9.383.1.2.32
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
Indicates whether the traffic from the attacker that triggered the alert would have been denied as a result of the alert if the intrusion prevention system was operating in inline mode. However, this action was not actually taken because the intrusion prevention system was operating in promiscuous mode. This element may be omitted if and only if its value is false.
cidsAlertBlockConnectionReq
1.3.6.1.4.1.9.9.383.1.2.33
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
Indicates that a TCP connection has been requested to be blocked as a result of the alert. This element may be omitted if and only if its value is false.
cidsAlertLogAttackerPacketsAct
1.3.6.1.4.1.9.9.383.1.2.34
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
Indicates that packets associated with the attacker(s) identified by this alert are being logged. This element may be omitted if and only if its value is false.
cidsAlertLogVictimPacketsAct
1.3.6.1.4.1.9.9.383.1.2.35
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
Indicates that packets associated with the victim(s) identified by this alert are being logged. This element may be omitted if and only if its value is false.
cidsAlertLogPairPacketsActivated
1.3.6.1.4.1.9.9.383.1.2.36
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
Indicates that packets associated with the attacker/victim pair(s) identified by this alert are being logged. This element may be omitted if and only if its value is false.
cidsAlertRateLimitRequested
1.3.6.1.4.1.9.9.383.1.2.37
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
Indicates that traffic rate limiting based on the source address and protocol associated with the alert has been requested on external network devices. This element may be omitted if and only if its value is false.
cidsAlertDeniedAttackVictimPair
1.3.6.1.4.1.9.9.383.1.2.38
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
Indicates that traffic from originating from the attackers address and destined for the victims address identified in the alert is being denied as a result of the alert. This element may be omitted if and only if its value is false.
cidsAlertDeniedAttackSericePair
1.3.6.1.4.1.9.9.383.1.2.39
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
Indicates that traffic from originating from the attackers address and destined for the destination service port identified in the alert is being denied as a result of the alert. This element may be omitted if and only if its value is false.
cidsAlertDenyAttackVicReqNotPerf
1.3.6.1.4.1.9.9.383.1.2.40
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
Indicates that traffic from originating from the attackers address and destined for the victims address identified in the alert would have been denied as a result of the alert if the intrusion prevention system was operating in inline mode. However, this action was not actually taken because the intrusion prevention system was operating in promiscuous mode. This element may be omitted if and only if its value is false.
cidsAlertDenyAttackSerReqNotPerf
1.3.6.1.4.1.9.9.383.1.2.41
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
Indicates that traffic from originating from the attackers address and destined for the destination service port identified in the alert would have been denied as a result of the alert if the intrusion prevention system was operating in inline mode. However, this action was not actually taken because the intrusion prevention system was operating in promiscuous mode. This element may be omitted if and only if its value is false.
cidsAlertThreatValueRating
1.3.6.1.4.1.9.9.383.1.2.42
Unsigned32
Value that represents the calculated threat associated with the detected activity. The threat value consists of the cidsAlertEventRiskRating adjusted for the mitigation action performed. The threat value has a range between 0 and 100 (inclusive), where a value of 0 represents the lowest threat and 100 the greatest threat.
cidsAlertRiskRatingTargetValue
1.3.6.1.4.1.9.9.383.1.2.43
CidsTargetValue1 = zeroValue2 = low3 = medium4 = high5 = missionCriticalAn enumerated value which identifies the asset value associated with a target.
zeroValue Target has zero perceived value to the network. low Target has low perceived value to the network. medium Target has medium perceived value to the network. high Target has high perceived value to the network. missionCritical Target is a mission critical component in the network. · Integer32
Represents the asset value associated with a target identified in the alert.
cidsAlertRiskRatingRelevance
1.3.6.1.4.1.9.9.383.1.2.44
CidsAttackRelevance1 = relevant2 = notRelevant3 = unknownAn enumerated value which identifies an attack's relevance to its target.
relevant The attack is relevant to the target. notRelevant The attack is not relevant to the target. unknown The relevancy of the attack is unknown. · Integer32
Value that represents an attack's relevance to the destination target of this alert.
cidsAlertRiskRatingWatchList
1.3.6.1.4.1.9.9.383.1.2.45
Unsigned32
Value that represents the amount that the risk rating value was increased due to the source of the activity associated with the alert being on a watchlist.
cidsAlertDenyPacket
1.3.6.1.4.1.9.9.383.1.2.46
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
This object indicates that the traffic originating from the attacker is being blocked as a result of the alert. This element may be omitted if and only if its value is 'false'.
cidsAlertBlockHost
1.3.6.1.4.1.9.9.383.1.2.47
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
This object indicates that a host has been requested to be blocked as a result of the alert. This element may be omitted if and only if its value is 'false'.
cidsAlertTcpOneWayResetSent
1.3.6.1.4.1.9.9.383.1.2.48
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
This object indicates an attempt to reset one side of the connection (the victim side). The victim address and ports affected must be implied from the information contained in the participant elements of the alert. This element may be omitted if and only if its value is 'false'.
cidsAlertVirtualSensor
1.3.6.1.4.1.9.9.383.1.2.49
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (1..64) · OCTET STRING · hint 255t
This object represents the name of the virtual sensor associated with an Intrusion Prevention System alert. From the virtual sensor name one can correlate which signature set and configuration to look at to trouble shoot or tune the behavior of the sensor. The virtual sensor name with the signature ID should help in identifying the correct instance of the signature that fired the alert.
cidsErrorSeverity
1.3.6.1.4.1.9.9.383.1.3.1
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
Severity of an error (warning, error or fatal for example). An example of a type of error that could occur would be when a requested action could not be completed because it would create a resource that would exceed a system resource limit.
cidsErrorName
1.3.6.1.4.1.9.9.383.1.3.2
CidsErrorCode1 = errAuthenticationTokenExpired2 = errConfigCollision3 = errInUse4 = errInvalidDocument5 = errLimitExceeded6 = errNotAvailable7 = errNotFound8 = errNotSupported9 = errPermissionDenied10 = errSyslog11 = errSystemError12 = errTransport13 = errUnacceptableValue14 = errUnclassified15 = errWarning16 = errEngineBuildFailedAn enumerated value which identifies the general category of error that occurred.
errAuthenticationTokenExpired The requested action could not be carried out because the requestor has provided an authentication token (e.g. password) that has expired. errConfigCollision The value of the config-token request parameter in a setComponentConfig control transaction request does not match the current configuration document on the target host. Typically this indicates that the configuration on the target host has been modified by another user. errInUse The requested action could not be completed because it requires access to a resource that is in use. errInvalidDocument The request contained a document that was not well-formed, contained an incorrect root element, or contained additional elements or attributes that are not permitted by the lax IDIOM schema. errLimitExceeded The requested action could not be completed because it would create a resource that would exceed a system resource limit. errNotAvailable The requested action is supported but cannot be performed due to the current configuration of the target host. errNotFound A resource specified in the request does not exist. errNotSupported The requested action is not supported on the target host. errPermissionDenied The requestor does not have a sufficiently high authorization level to perform the requested action. errSyslog Used to convey messages of interest from the host system's syslog. errSystemError A system error occurred, such as an out-of-memory condition, disk access error, etc. errTransport The requested action could not be carried out because of a communications failure with another host that is involved in the action. errUnacceptableValue The request document was valid but contained one or more values that could not be accepted because they either: (1) conflict with other values in the same document or (2) are not acceptable due to the current state of the system. errUnclassified Used to convey an unclassified error condition. errWarning Used to convey a software warning condition detected by an application running on the host system. errEngineBuildFailed The system failed to build an intrusion detection engine. · Integer32
An enumerated error code, which identifies a general class of errors.
cidsErrorMessage
1.3.6.1.4.1.9.9.383.1.3.3
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
A textual description of the error that occurred.
cidsHealthPacketLoss
1.3.6.1.4.1.9.9.383.1.4.1
Integer32 (0..100) · percent
The percentage of packets lost at the device interface level.
cidsHealthPacketDenialRate
1.3.6.1.4.1.9.9.383.1.4.2
Integer32 (0..100) · percent
The percentage of packets denied due to protocol and security violations.
cidsHealthAlarmsGenerated
1.3.6.1.4.1.9.9.383.1.4.3
Counter32
The number of alarms generated, includes all currently defined alarm severities.
cidsHealthFragmentsInFRU
1.3.6.1.4.1.9.9.383.1.4.4
Gauge32
The number of fragments currently queued in the fragment reassembly unit.
cidsHealthDatagramsInFRU
1.3.6.1.4.1.9.9.383.1.4.5
Gauge32
The number of datagrams currently queued in the fragment reassembly unit.
cidsHealthTcpEmbryonicStreams
1.3.6.1.4.1.9.9.383.1.4.6
Gauge32
The number of embryonic TCP streams currently queued in the device. TCP streams are considered embryonic if they have not completed the TCP three-way handshake.
cidsHealthTCPEstablishedStreams
1.3.6.1.4.1.9.9.383.1.4.7
Gauge32
The number of established TCP streams currently queued in the device. Once a stream has completed a TCP three-way handshake it will move to the established state.
cidsHealthTcpClosingStreams
1.3.6.1.4.1.9.9.383.1.4.8
Gauge32
The number of closing TCP streams currently queued in the device. A stream will move from the established state to closing when a valid FIN or RST flag is received.
cidsHealthTcpStreams
1.3.6.1.4.1.9.9.383.1.4.9
Gauge32
The number of TCP streams (embryonic, established and closing) currently queued in the device.
cidsHealthActiveNodes
1.3.6.1.4.1.9.9.383.1.4.10
Gauge32
The number of active nodes currently queued in the device.
cidsHealthTcpDualIpAndPorts
1.3.6.1.4.1.9.9.383.1.4.11
Gauge32
The number TCP nodes keyed on both IP addresses and both ports currently queued in the device.
cidsHealthUdpDualIpAndPorts
1.3.6.1.4.1.9.9.383.1.4.12
Gauge32
The number UDP nodes keyed on both IP addresses and both ports currently queued in the device.
cidsHealthIpDualIp
1.3.6.1.4.1.9.9.383.1.4.13
Gauge32
The number IP nodes keyed on both IP addresses currently queued in the device.
cidsHealthIsSensorMemoryCritical
1.3.6.1.4.1.9.9.383.1.4.14
Unsigned32 (0..10)
A value between 0 and 10 that should rarely get above 3. If this is non-zero the sensor has stopped enforcing policy on some traffic in order to keep up with the current traffic load; the sensor is oversubscribed. The higher the number the more oversubscribed the sensor. It could be oversubscribed from a memory prospective and not traffic speed. For example on a 200 Mbit sensor this number might be 3 if the sensor was only seeing 100Mbit of traffic but 6000 connections per second which is over the rated capacity of the sensor. When the sensor is in Memory Critical state then a ciscoCidsError trap will be sent accordingly.
cidsHealthIsSensorActive
1.3.6.1.4.1.9.9.383.1.4.15
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
Indicates the failover status of the device. True indicates the device is currently active. False indicates it is in a standby mode.
cidsHealthCommandAndControlPort
1.3.6.1.4.1.9.9.383.1.4.16
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The status and network statistics of the currently configured Command and Control interface on the device. The Command and Control interface is where all of the communications for command and control of the sensor occurs. This is important to identify what interface a user will communicate with to control the sensor remotely and general health statistics for that interface.
cidsHealthSensorStatsResetTime
1.3.6.1.4.1.9.9.383.1.4.17
TimeTicks
The value of SNMPv2-MIB::sysUpTime when the Sensor specific statistics was reset. The reset time is collectively for the following objects: cidsHealthPacketLoss, cidsHealthPacketDenies, cidsHealthAlarmsGenerated, cidsHealthFragmentsInFRU, cidsHealthDatagramsInFRU, cidsHealthTcpEmbryonicStreams, cidsHealthTcpEstablishedStreams, cidsHealthTcpClosingStreams, cidsHealthTcpStreams
cidsHealthSecMonAvailability
1.3.6.1.4.1.9.9.383.1.4.18
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
This object indicates the availability of health and security monitor statistics. If the IPS health and security monitoring service is disabled, it will return false.
cidsHealthSecMonOverallHealth
1.3.6.1.4.1.9.9.383.1.4.19
CidsHealthStatusColor1 = green2 = yellow3 = redAn enumerated value which identifies the status colors for health related statistics. The colors are chosen since they are commonly used in health dashboards when visualizing the status of a component and should generally be understood.
green Indicates sensor health status is good and currently no issues.
yellow Indicates degrade in health status. please monitor closely until the status changes back to green.
red A problem has occurred and the status is unhealthy immediate attention is needed. · Integer32
This object indicates IPS sensor's overall health value - green, yellow or red. The overall health status is set to the highest severity of all metrics that are configured to be applied to the IPS's health determination. For example, if the IPS is configured to use eight metrics to determine its health and seven of eight metrics are green while one of the metrics is red then the overall IPS health will be red.
This object is instantiated only if the value of cidsHealthSecMonAvailability is set to 'true'.
cidsHealthSecMonSoftwareVersion
1.3.6.1.4.1.9.9.383.1.4.20
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..32) · OCTET STRING · hint 255a
This object indicates the IPS software version number (e.g., 6.2(1)E3).
This object is instantiated only if the value of cidsHealthSecMonAvailability is set to 'true'.
cidsHealthSecMonSignatureVersion
1.3.6.1.4.1.9.9.383.1.4.21
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
This object indicates IPS signature version (e.g., 365.0).
This object is instantiated only if the value of cidsHealthSecMonAvailability is set to 'true'.
cidsHealthSecMonLicenseStatus
1.3.6.1.4.1.9.9.383.1.4.22
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
This object indicates IPS license status along with expiration date. For example it will contain the following possible values:
- signatureUpdateKey: Not expired until: <timestamp> - trialKey: Not expired until: <timestamp> - expiredLicense - noLicense - invalidLicense - unknown
The timestamp will be in the format: MM/DD/YYYY HH:MM:SS
This object is instantiated only if the value of cidsHealthSecMonAvailability is set to 'true'.
cidsHealthSecMonOverallAppColor
1.3.6.1.4.1.9.9.383.1.4.23
CidsHealthStatusColor1 = green2 = yellow3 = redAn enumerated value which identifies the status colors for health related statistics. The colors are chosen since they are commonly used in health dashboards when visualizing the status of a component and should generally be understood.
green Indicates sensor health status is good and currently no issues.
yellow Indicates degrade in health status. please monitor closely until the status changes back to green.
red A problem has occurred and the status is unhealthy immediate attention is needed. · Integer32
This object indicates the aggregate health status of the applications - Main, Analysis Engine, Collaboration - where the status is equal to the most severe status of all three applications. It is used in both the heart beat and the metric change health traps.
cidsHealthSecMonMainAppStatus
1.3.6.1.4.1.9.9.383.1.4.24
CidsApplicationStatus1 = notResponding2 = notRunning3 = processingTransaction4 = reconfiguring5 = running6 = starting7 = stopping8 = unknown9 = upgradeInprogressAn enumerated value which identifies the status values that are possible for a process.
notResponding The process is no longer responding and may be down.
notRunning The process is not currently running.
processingTransaction The process is currently processing a control transaction.
reconfiguring The configuration for this process is being changed.
running The process is up and running.
starting The process is starting and will be up and running momentarily.
stopping The process is currently being shut down.
unknown Unable to determine the current process status.
upgradeInprogress The process is currently being upgraded. · Integer32
This object indicates the running status for the control plane.
This object is instantiated only if the value of cidsHealthSecMonAvailability is set to 'true'.
cidsHealthSecMonAnalysisEngineStatus
1.3.6.1.4.1.9.9.383.1.4.25
CidsApplicationStatus1 = notResponding2 = notRunning3 = processingTransaction4 = reconfiguring5 = running6 = starting7 = stopping8 = unknown9 = upgradeInprogressAn enumerated value which identifies the status values that are possible for a process.
notResponding The process is no longer responding and may be down.
notRunning The process is not currently running.
processingTransaction The process is currently processing a control transaction.
reconfiguring The configuration for this process is being changed.
running The process is up and running.
starting The process is starting and will be up and running momentarily.
stopping The process is currently being shut down.
unknown Unable to determine the current process status.
upgradeInprogress The process is currently being upgraded. · Integer32
This object indicates the running status for the Analysis Engine.
This object is instantiated only if the value of cidsHealthSecMonAvailability is set to 'true'.
cidsHealthSecMonCollaborationAppStatus
1.3.6.1.4.1.9.9.383.1.4.26
CidsApplicationStatus1 = notResponding2 = notRunning3 = processingTransaction4 = reconfiguring5 = running6 = starting7 = stopping8 = unknown9 = upgradeInprogressAn enumerated value which identifies the status values that are possible for a process.
notResponding The process is no longer responding and may be down.
notRunning The process is not currently running.
processingTransaction The process is currently processing a control transaction.
reconfiguring The configuration for this process is being changed.
running The process is up and running.
starting The process is starting and will be up and running momentarily.
stopping The process is currently being shut down.
unknown Unable to determine the current process status.
upgradeInprogress The process is currently being upgraded. · Integer32
This object indicates the running status for the Collaboration Application.
This object is instantiated only if the value of cidsHealthSecMonAvailability is set to 'true'.
cidsHealthSecMonByPassMode
1.3.6.1.4.1.9.9.383.1.4.27
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
This object indicates the bypass mode. A value of 'true' indicates bypass mode is on and a value of 'false' indicates it is off.
This object is instantiated only if the value of cidsHealthSecMonAvailability is set to 'true'.
cidsHealthSecMonMissedPktPctAndThresh
1.3.6.1.4.1.9.9.383.1.4.28
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
This object indicates the missed packet percentage and missed packets percentage threshold aggregated for all interfaces. For example, 'missedPacketPercentage=1 redThreshold=6 yellowThreshold=1'.
This object is instantiated only if the value of cidsHealthSecMonAvailability is set to 'true'.
cidsHealthSecMonAnalysisEngMemPercent
1.3.6.1.4.1.9.9.383.1.4.29
Integer32 (0..100) · percent
This object indicates the percentage of memory used by Analysis Engine.
This object is instantiated only if the value of cidsHealthSecMonAvailability is set to 'true'.
cidsHealthSecMonSensorLoad
1.3.6.1.4.1.9.9.383.1.4.30
Integer32 (0..100)
This object indicates sensor inspection load.
This object is instantiated only if the value of cidsHealthSecMonAvailability is set to 'true'.
cidsHealthSecMonSensorLoadColor
1.3.6.1.4.1.9.9.383.1.4.31
CidsHealthStatusColor1 = green2 = yellow3 = redAn enumerated value which identifies the status colors for health related statistics. The colors are chosen since they are commonly used in health dashboards when visualizing the status of a component and should generally be understood.
green Indicates sensor health status is good and currently no issues.
yellow Indicates degrade in health status. please monitor closely until the status changes back to green.
red A problem has occurred and the status is unhealthy immediate attention is needed. · Integer32
This object indicates the status of current sensor load, indicated using status colors. The color is determined based on the sensor load percentage and configured threshold value.
Table details
cidsHealthSecMonVirtSensorStatusTable
1.3.6.1.4.1.9.9.383.1.4.32
Index: cidsHealthSecMonVirtSensorName
This table contains the status of each virtual sensor. There will be one entry per virtual sensor in the system. This is the status of the network that the virtual sensor is monitoring. A virtual sensor can be added either through the configuration CLI or through a management application such as IME/CSM; once it is added to the system it will appear in this table. If a virtual sensor is removed from the system through one of the management interfaces it will no longer appear in this table.
This table is instantiated only if the value of cidsHealthSecMonAvailability is set to 'true'.
cidsHealthSecMonVirtSensorName
1.3.6.1.4.1.9.9.383.1.4.32.1.1
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (1..64) · OCTET STRING · hint 255a
This object represents the name of the virtual sensor. Through the IPS configuration the sensor name can be correlated with the
sensor configuration and the associated interfaces to identify which networks are having good or bad health status. The reason there are multiple virtual sensor configurations is to allow different configurations for different sets of network interfaces.
cidsHealthSecMonVirtSensorStatus
1.3.6.1.4.1.9.9.383.1.4.32.1.2
CidsHealthStatusColor1 = green2 = yellow3 = redAn enumerated value which identifies the status colors for health related statistics. The colors are chosen since they are commonly used in health dashboards when visualizing the status of a component and should generally be understood.
green Indicates sensor health status is good and currently no issues.
yellow Indicates degrade in health status. please monitor closely until the status changes back to green.
red A problem has occurred and the status is unhealthy immediate attention is needed. · Integer32
This object represents the virtual sensor network status level. From the color rating associated with the virtual sensor you can determine the overall health of the attached networks. If the color is green everything is fine, the IPS is not indicating a problem. If the color is yellow you should check as there maybe issues occuring on the attached network. If the status is red the network needs attention as problems are detected and network security is critical.
cidsHealthSecMonDataStorageTable
1.3.6.1.4.1.9.9.383.1.4.33
Index: cidsHealthSecMonPartitionName
This is the table of disk partition details:
Partition Name Total Space In Partition Utilized Space
This table tells how each of the file systems are utilized on the IPS. If the file systems approach 100% utilization that may indicate a problem. This table should remain fixed size unless an upgrade/install changes the partition count. The user does not have control over the number of partitions or the ability to add and remove partitions.
This table is instantiated only if the value of cidsHealthSecMonAvailability is set to 'true'.
cidsHealthSecMonPartitionName
1.3.6.1.4.1.9.9.383.1.4.33.1.1
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (1..64) · OCTET STRING · hint 255a
Name of the disk partition. For example: system application-data boot application-log
cidsHealthSecMonTotalPartitionSpace
1.3.6.1.4.1.9.9.383.1.4.33.1.2
Unsigned32 · MB
This object represents the total disk space on the partition in megabytes.
cidsHealthSecMonUtilizedPartitionSpace
1.3.6.1.4.1.9.9.383.1.4.33.1.3
Unsigned32 · MB
This object represents the total amount of utilized disk space in megabytes.
Trap details
ciscoCidsAlert
1.3.6.1.4.1.9.9.383.0.1
Event indicating that some suspicious or malicious activity has been detected on a monitored network.
cidsGeneralEventId
1.3.6.1.4.1.9.9.383.1.1.1
Unsigned64An unsigned 64 bit integer. We use SYNTAX Counter64 for the encoding rules. (0..18446744073709551615) · Counter64
Identifies the sequence number of an event. This value needs to be unique within the scope of the originating host.
cidsGeneralLocalTime
1.3.6.1.4.1.9.9.383.1.1.2
DateAndTimeA date-time specification.
field octets contents range
----- ------ -------- -----
1 1-2 year* 0..65536
2 3 month 1..12
3 4 day 1..31
4 5 hour 0..23
5 6 minutes 0..59
6 7 seconds 0..60
(use 60 for leap-second)
7 8 deci-seconds 0..9
8 9 direction from UTC '+' / '-'
9 10 hours from UTC* 0..13
10 11 minutes from UTC 0..59
* Notes: - the value of year is in network-byte order - daylight saving time in New Zealand is +13
For example, Tuesday May 26, 1992 at 1:30:15 PM EDT would be displayed as:
1992-5-26,13:30:15.0,-4:0
Note that if only local time is known, then timezone information (fields 8-10) is not present. SIZE (8 | 11) · OCTET STRING · hint 2d-1d-1d,1d:1d:1d.1d,1a1d:1d
The local time on the Cisco intrusion detection system sensor when the alert was generated.
cidsGeneralUTCTime
1.3.6.1.4.1.9.9.383.1.1.3
DateAndTimeA date-time specification.
field octets contents range
----- ------ -------- -----
1 1-2 year* 0..65536
2 3 month 1..12
3 4 day 1..31
4 5 hour 0..23
5 6 minutes 0..59
6 7 seconds 0..60
(use 60 for leap-second)
7 8 deci-seconds 0..9
8 9 direction from UTC '+' / '-'
9 10 hours from UTC* 0..13
10 11 minutes from UTC 0..59
* Notes: - the value of year is in network-byte order - daylight saving time in New Zealand is +13
For example, Tuesday May 26, 1992 at 1:30:15 PM EDT would be displayed as:
1992-5-26,13:30:15.0,-4:0
Note that if only local time is known, then timezone information (fields 8-10) is not present. SIZE (8 | 11) · OCTET STRING · hint 2d-1d-1d,1d:1d:1d.1d,1a1d:1d
The UTC time on the Cisco intrusion detection system sensor when the alert was generated.
cidsGeneralOriginatorHostId
1.3.6.1.4.1.9.9.383.1.1.4
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
A globally unique identifier for a Cids host. Could be a host name or an IP address.
cidsAlertSeverity
1.3.6.1.4.1.9.9.383.1.2.1
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The severity associated with a Cids signature (informational, low, medium or high for example).
cidsAlertSignatureSigName
1.3.6.1.4.1.9.9.383.1.2.4
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (1..64) · OCTET STRING · hint 255t
The name of the Intrusion detection signature that triggered this event.
cidsAlertSignatureSigId
1.3.6.1.4.1.9.9.383.1.2.5
Unsigned32
The ID of the Intrusion detection signature that triggered this event. The ID combines with the cidsAlertSignatureSubSigId to create a unique key that identifies the signature that generated this event.
cidsAlertSignatureSubSigId
1.3.6.1.4.1.9.9.383.1.2.6
Unsigned32
The optional Sub ID of the Intrusion detection signature that triggered this event. The Sub ID combines with the cidsAlertSignatureSigId to create a unique key that identifies the signature that generated this event.
cidsAlertAlarmTraits
1.3.6.1.4.1.9.9.383.1.2.2
Unsigned32
The alarm traits is an unsigned 16-bit integer representing the value of the 16 user-defined alarm traits specified in the configuration for the signature that triggered the alert. The alarmTraits bits are used to classify signatures into user-defined categories or groups.
cidsAlertAttackerAddress
1.3.6.1.4.1.9.9.383.1.2.16
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
Optional IP address and ports on a monitored interface. The 'locality' attribute is a string that indicates the relative location of the IP address within the network mapping, such as whether the address falls within the address range of a protected network. The optional 'proxy' attribute is 'true' if the sensor has reason to suspect that the address given is not the address of the true attacker. This could be a the result of address spoofing or because the host has been compromised and is acting as a 'zombie'. The 'proxy' attribute may be omitted if and only if its value is false.
cidsAlertVictimAddress
1.3.6.1.4.1.9.9.383.1.2.17
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
Optional IP address and ports on a monitored interface. The 'locality' attribute is a string that indicates the relative location of the IP address within the network mapping, such as whether the address falls within the address range of a protected network. The 'osIdSource' attribute represents the method that the operating system of the victim was identified. The 'osType' attribute represents the operating system of the target system. The 'osRelevance' attribute represents the relevance of an attack on the operating system.
ciscoCidsError
1.3.6.1.4.1.9.9.383.0.2
Event indicating that an error has occurred.
cidsGeneralEventId
1.3.6.1.4.1.9.9.383.1.1.1
Unsigned64An unsigned 64 bit integer. We use SYNTAX Counter64 for the encoding rules. (0..18446744073709551615) · Counter64
Identifies the sequence number of an event. This value needs to be unique within the scope of the originating host.
cidsGeneralLocalTime
1.3.6.1.4.1.9.9.383.1.1.2
DateAndTimeA date-time specification.
field octets contents range
----- ------ -------- -----
1 1-2 year* 0..65536
2 3 month 1..12
3 4 day 1..31
4 5 hour 0..23
5 6 minutes 0..59
6 7 seconds 0..60
(use 60 for leap-second)
7 8 deci-seconds 0..9
8 9 direction from UTC '+' / '-'
9 10 hours from UTC* 0..13
10 11 minutes from UTC 0..59
* Notes: - the value of year is in network-byte order - daylight saving time in New Zealand is +13
For example, Tuesday May 26, 1992 at 1:30:15 PM EDT would be displayed as:
1992-5-26,13:30:15.0,-4:0
Note that if only local time is known, then timezone information (fields 8-10) is not present. SIZE (8 | 11) · OCTET STRING · hint 2d-1d-1d,1d:1d:1d.1d,1a1d:1d
The local time on the Cisco intrusion detection system sensor when the alert was generated.
cidsGeneralUTCTime
1.3.6.1.4.1.9.9.383.1.1.3
DateAndTimeA date-time specification.
field octets contents range
----- ------ -------- -----
1 1-2 year* 0..65536
2 3 month 1..12
3 4 day 1..31
4 5 hour 0..23
5 6 minutes 0..59
6 7 seconds 0..60
(use 60 for leap-second)
7 8 deci-seconds 0..9
8 9 direction from UTC '+' / '-'
9 10 hours from UTC* 0..13
10 11 minutes from UTC 0..59
* Notes: - the value of year is in network-byte order - daylight saving time in New Zealand is +13
For example, Tuesday May 26, 1992 at 1:30:15 PM EDT would be displayed as:
1992-5-26,13:30:15.0,-4:0
Note that if only local time is known, then timezone information (fields 8-10) is not present. SIZE (8 | 11) · OCTET STRING · hint 2d-1d-1d,1d:1d:1d.1d,1a1d:1d
The UTC time on the Cisco intrusion detection system sensor when the alert was generated.
cidsGeneralOriginatorHostId
1.3.6.1.4.1.9.9.383.1.1.4
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
A globally unique identifier for a Cids host. Could be a host name or an IP address.
cidsErrorSeverity
1.3.6.1.4.1.9.9.383.1.3.1
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
Severity of an error (warning, error or fatal for example). An example of a type of error that could occur would be when a requested action could not be completed because it would create a resource that would exceed a system resource limit.
cidsErrorName
1.3.6.1.4.1.9.9.383.1.3.2
CidsErrorCode1 = errAuthenticationTokenExpired2 = errConfigCollision3 = errInUse4 = errInvalidDocument5 = errLimitExceeded6 = errNotAvailable7 = errNotFound8 = errNotSupported9 = errPermissionDenied10 = errSyslog11 = errSystemError12 = errTransport13 = errUnacceptableValue14 = errUnclassified15 = errWarning16 = errEngineBuildFailedAn enumerated value which identifies the general category of error that occurred.
errAuthenticationTokenExpired The requested action could not be carried out because the requestor has provided an authentication token (e.g. password) that has expired. errConfigCollision The value of the config-token request parameter in a setComponentConfig control transaction request does not match the current configuration document on the target host. Typically this indicates that the configuration on the target host has been modified by another user. errInUse The requested action could not be completed because it requires access to a resource that is in use. errInvalidDocument The request contained a document that was not well-formed, contained an incorrect root element, or contained additional elements or attributes that are not permitted by the lax IDIOM schema. errLimitExceeded The requested action could not be completed because it would create a resource that would exceed a system resource limit. errNotAvailable The requested action is supported but cannot be performed due to the current configuration of the target host. errNotFound A resource specified in the request does not exist. errNotSupported The requested action is not supported on the target host. errPermissionDenied The requestor does not have a sufficiently high authorization level to perform the requested action. errSyslog Used to convey messages of interest from the host system's syslog. errSystemError A system error occurred, such as an out-of-memory condition, disk access error, etc. errTransport The requested action could not be carried out because of a communications failure with another host that is involved in the action. errUnacceptableValue The request document was valid but contained one or more values that could not be accepted because they either: (1) conflict with other values in the same document or (2) are not acceptable due to the current state of the system. errUnclassified Used to convey an unclassified error condition. errWarning Used to convey a software warning condition detected by an application running on the host system. errEngineBuildFailed The system failed to build an intrusion detection engine. · Integer32
An enumerated error code, which identifies a general class of errors.
cidsErrorMessage
1.3.6.1.4.1.9.9.383.1.3.3
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
A textual description of the error that occurred.
ciscoCidsHealthHeartBeat
1.3.6.1.4.1.9.9.383.0.3
This notification is triggered by the heart beat events (evStatus). The heartbeat is configured to run on a periodic basis and can be enabled/disabled through heart beat configuration under the health service. If the heart beat is disabled these notification events will not be sent.
This notification is supposed to mirror the heart beat evStatus message however it is a subset of the most critical pieces of data. Namely this will include the following pieces of data:
- Event ID - Host ID - Local Time - UTC Time - Overall Application Color - Sensor/Inspection Load Color - Overall Health
cidsGeneralEventId
1.3.6.1.4.1.9.9.383.1.1.1
Unsigned64An unsigned 64 bit integer. We use SYNTAX Counter64 for the encoding rules. (0..18446744073709551615) · Counter64
Identifies the sequence number of an event. This value needs to be unique within the scope of the originating host.
cidsGeneralOriginatorHostId
1.3.6.1.4.1.9.9.383.1.1.4
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
A globally unique identifier for a Cids host. Could be a host name or an IP address.
cidsGeneralLocalTime
1.3.6.1.4.1.9.9.383.1.1.2
DateAndTimeA date-time specification.
field octets contents range
----- ------ -------- -----
1 1-2 year* 0..65536
2 3 month 1..12
3 4 day 1..31
4 5 hour 0..23
5 6 minutes 0..59
6 7 seconds 0..60
(use 60 for leap-second)
7 8 deci-seconds 0..9
8 9 direction from UTC '+' / '-'
9 10 hours from UTC* 0..13
10 11 minutes from UTC 0..59
* Notes: - the value of year is in network-byte order - daylight saving time in New Zealand is +13
For example, Tuesday May 26, 1992 at 1:30:15 PM EDT would be displayed as:
1992-5-26,13:30:15.0,-4:0
Note that if only local time is known, then timezone information (fields 8-10) is not present. SIZE (8 | 11) · OCTET STRING · hint 2d-1d-1d,1d:1d:1d.1d,1a1d:1d
The local time on the Cisco intrusion detection system sensor when the alert was generated.
cidsGeneralUTCTime
1.3.6.1.4.1.9.9.383.1.1.3
DateAndTimeA date-time specification.
field octets contents range
----- ------ -------- -----
1 1-2 year* 0..65536
2 3 month 1..12
3 4 day 1..31
4 5 hour 0..23
5 6 minutes 0..59
6 7 seconds 0..60
(use 60 for leap-second)
7 8 deci-seconds 0..9
8 9 direction from UTC '+' / '-'
9 10 hours from UTC* 0..13
10 11 minutes from UTC 0..59
* Notes: - the value of year is in network-byte order - daylight saving time in New Zealand is +13
For example, Tuesday May 26, 1992 at 1:30:15 PM EDT would be displayed as:
1992-5-26,13:30:15.0,-4:0
Note that if only local time is known, then timezone information (fields 8-10) is not present. SIZE (8 | 11) · OCTET STRING · hint 2d-1d-1d,1d:1d:1d.1d,1a1d:1d
The UTC time on the Cisco intrusion detection system sensor when the alert was generated.
cidsHealthSecMonOverallAppColor
1.3.6.1.4.1.9.9.383.1.4.23
CidsHealthStatusColor1 = green2 = yellow3 = redAn enumerated value which identifies the status colors for health related statistics. The colors are chosen since they are commonly used in health dashboards when visualizing the status of a component and should generally be understood.
green Indicates sensor health status is good and currently no issues.
yellow Indicates degrade in health status. please monitor closely until the status changes back to green.
red A problem has occurred and the status is unhealthy immediate attention is needed. · Integer32
This object indicates the aggregate health status of the applications - Main, Analysis Engine, Collaboration - where the status is equal to the most severe status of all three applications. It is used in both the heart beat and the metric change health traps.
cidsHealthSecMonSensorLoadColor
1.3.6.1.4.1.9.9.383.1.4.31
CidsHealthStatusColor1 = green2 = yellow3 = redAn enumerated value which identifies the status colors for health related statistics. The colors are chosen since they are commonly used in health dashboards when visualizing the status of a component and should generally be understood.
green Indicates sensor health status is good and currently no issues.
yellow Indicates degrade in health status. please monitor closely until the status changes back to green.
red A problem has occurred and the status is unhealthy immediate attention is needed. · Integer32
This object indicates the status of current sensor load, indicated using status colors. The color is determined based on the sensor load percentage and configured threshold value.
cidsHealthSecMonOverallHealth
1.3.6.1.4.1.9.9.383.1.4.19
CidsHealthStatusColor1 = green2 = yellow3 = redAn enumerated value which identifies the status colors for health related statistics. The colors are chosen since they are commonly used in health dashboards when visualizing the status of a component and should generally be understood.
green Indicates sensor health status is good and currently no issues.
yellow Indicates degrade in health status. please monitor closely until the status changes back to green.
red A problem has occurred and the status is unhealthy immediate attention is needed. · Integer32
This object indicates IPS sensor's overall health value - green, yellow or red. The overall health status is set to the highest severity of all metrics that are configured to be applied to the IPS's health determination. For example, if the IPS is configured to use eight metrics to determine its health and seven of eight metrics are green while one of the metrics is red then the overall IPS health will be red.
This object is instantiated only if the value of cidsHealthSecMonAvailability is set to 'true'.
ciscoCidsHealthMetricChange
1.3.6.1.4.1.9.9.383.0.4
This notification notifies the recipient of health and security status changes. This notification is triggered when there is a change in the value of monitored metrics as indicated by evStatus message. This notification will include the following important subset of attributes from evStatus message:
- Event ID - Host ID - Local Time - UTC Time - Overall Application Color - Sensor/Inspection Load Color - Overall Health
This is similar to the heart beat, however the triggering condition is different. The heart beat fires on a regular interval and this is sent immediately after a change in a monitored metric. Metric change notifications can be enabled while the heart beat is disabled.
cidsGeneralEventId
1.3.6.1.4.1.9.9.383.1.1.1
Unsigned64An unsigned 64 bit integer. We use SYNTAX Counter64 for the encoding rules. (0..18446744073709551615) · Counter64
Identifies the sequence number of an event. This value needs to be unique within the scope of the originating host.
cidsGeneralOriginatorHostId
1.3.6.1.4.1.9.9.383.1.1.4
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
A globally unique identifier for a Cids host. Could be a host name or an IP address.
cidsGeneralLocalTime
1.3.6.1.4.1.9.9.383.1.1.2
DateAndTimeA date-time specification.
field octets contents range
----- ------ -------- -----
1 1-2 year* 0..65536
2 3 month 1..12
3 4 day 1..31
4 5 hour 0..23
5 6 minutes 0..59
6 7 seconds 0..60
(use 60 for leap-second)
7 8 deci-seconds 0..9
8 9 direction from UTC '+' / '-'
9 10 hours from UTC* 0..13
10 11 minutes from UTC 0..59
* Notes: - the value of year is in network-byte order - daylight saving time in New Zealand is +13
For example, Tuesday May 26, 1992 at 1:30:15 PM EDT would be displayed as:
1992-5-26,13:30:15.0,-4:0
Note that if only local time is known, then timezone information (fields 8-10) is not present. SIZE (8 | 11) · OCTET STRING · hint 2d-1d-1d,1d:1d:1d.1d,1a1d:1d
The local time on the Cisco intrusion detection system sensor when the alert was generated.
cidsGeneralUTCTime
1.3.6.1.4.1.9.9.383.1.1.3
DateAndTimeA date-time specification.
field octets contents range
----- ------ -------- -----
1 1-2 year* 0..65536
2 3 month 1..12
3 4 day 1..31
4 5 hour 0..23
5 6 minutes 0..59
6 7 seconds 0..60
(use 60 for leap-second)
7 8 deci-seconds 0..9
8 9 direction from UTC '+' / '-'
9 10 hours from UTC* 0..13
10 11 minutes from UTC 0..59
* Notes: - the value of year is in network-byte order - daylight saving time in New Zealand is +13
For example, Tuesday May 26, 1992 at 1:30:15 PM EDT would be displayed as:
1992-5-26,13:30:15.0,-4:0
Note that if only local time is known, then timezone information (fields 8-10) is not present. SIZE (8 | 11) · OCTET STRING · hint 2d-1d-1d,1d:1d:1d.1d,1a1d:1d
The UTC time on the Cisco intrusion detection system sensor when the alert was generated.
cidsHealthSecMonOverallAppColor
1.3.6.1.4.1.9.9.383.1.4.23
CidsHealthStatusColor1 = green2 = yellow3 = redAn enumerated value which identifies the status colors for health related statistics. The colors are chosen since they are commonly used in health dashboards when visualizing the status of a component and should generally be understood.
green Indicates sensor health status is good and currently no issues.
yellow Indicates degrade in health status. please monitor closely until the status changes back to green.
red A problem has occurred and the status is unhealthy immediate attention is needed. · Integer32
This object indicates the aggregate health status of the applications - Main, Analysis Engine, Collaboration - where the status is equal to the most severe status of all three applications. It is used in both the heart beat and the metric change health traps.
cidsHealthSecMonSensorLoadColor
1.3.6.1.4.1.9.9.383.1.4.31
CidsHealthStatusColor1 = green2 = yellow3 = redAn enumerated value which identifies the status colors for health related statistics. The colors are chosen since they are commonly used in health dashboards when visualizing the status of a component and should generally be understood.
green Indicates sensor health status is good and currently no issues.
yellow Indicates degrade in health status. please monitor closely until the status changes back to green.
red A problem has occurred and the status is unhealthy immediate attention is needed. · Integer32
This object indicates the status of current sensor load, indicated using status colors. The color is determined based on the sensor load percentage and configured threshold value.
cidsHealthSecMonOverallHealth
1.3.6.1.4.1.9.9.383.1.4.19
CidsHealthStatusColor1 = green2 = yellow3 = redAn enumerated value which identifies the status colors for health related statistics. The colors are chosen since they are commonly used in health dashboards when visualizing the status of a component and should generally be understood.
green Indicates sensor health status is good and currently no issues.
yellow Indicates degrade in health status. please monitor closely until the status changes back to green.
red A problem has occurred and the status is unhealthy immediate attention is needed. · Integer32
This object indicates IPS sensor's overall health value - green, yellow or red. The overall health status is set to the highest severity of all metrics that are configured to be applied to the IPS's health determination. For example, if the IPS is configured to use eight metrics to determine its health and seven of eight metrics are green while one of the metrics is red then the overall IPS health will be red.
This object is instantiated only if the value of cidsHealthSecMonAvailability is set to 'true'.