INTRUSION-DETECTION-ALERT-MIB
AI MIB Summary
INTRUSION-DETECTION-ALERT-MIB defines the standardized SNMP object definitions for transmitting real-time security alerts and event notifications from Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) to a network management station. It enables the monitoring of specific security metrics such as attack signatures, source/destination IP addresses, protocol anomalies, and alert severity levels to facilitate automated incident response and audit logging.
The MIB for Intrusion Detection Messages.
Main OID:
idMIB.1.3.6.1.2.1.1
120
Objects
Active
Status
5
Dependencies
Imported Objects
Objects
120 total| Object Name |
|---|
idMIBThe MIB for Intrusion Detection Messages. MODULE-IDENTITY .1.3.6.1.2.1.1 |
idAlertObjectsThis is the base object for the objects used in the alert notifications. OBJECT IDENTIFIER .1.3.6.1.2.1.1.1 |
idAlertTableEach row of this table contains information about an alert indexed by idAlertID. SEQUENCE OF IdAlertEntry .1.3.6.1.2.1.1.1.1 |
idAlertEntryEntry containing information pertaining to an alert. IdAlertEntry .1.3.6.1.2.1.1.1.1.1 |
idAlertVersionThe version of the class hierarchy used in defining the alert.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.1.1.1 |
idAlertIDThe AlertID uniquely identifies each alert generated by an analyzer.ro INTEGER .1.3.6.1.2.1.1.1.1.1.2 |
idAlertImpactAn indication of the impact of the (potential) impact of the event on the system.ro INTEGER .1.3.6.1.2.1.1.1.1.1.3 |
idTimeTableEach row of this table contains information about the time of an alert indexed by idAlertID. SEQUENCE OF IdTimeEntry .1.3.6.1.2.1.1.1.2 |
idTimeEntryEntry containing information pertaining to the time an alert was generated. IdTimeEntry .1.3.6.1.2.1.1.1.2.1 |
idTimeOffsetSpecifies the offset from Coordinated Universal Time UTC, formerly referred to as Greenwich Mean Time that the <date> and <time> elements represent.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.2.1.1 |
idTimeNtpStampThe NTP timestamp.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.2.1.2 |
idTimeDateThe Date.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.2.1.3 |
idTimeTimeThe Time.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.2.1.4 |
idDTimeTableEach row of this table contains information about the detection time of the event that caused the alert. SEQUENCE OF IdTimeEntry .1.3.6.1.2.1.1.1.3 |
idDTimeEntryEntry containing information pertaining to the time an event was detected. IdDTimeEntry .1.3.6.1.2.1.1.1.3.1 |
idDTimeOffsetSpecifies the offset from Coordinated Universal Time UTC, that the idTimeDate and idTimeTime elements it represents.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.3.1.1 |
idDTimeNtpStampThe NTP timestamp.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.3.1.2 |
idDTimeDateThe Date.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.3.1.3 |
idDTimeTimeThe Time.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.3.1.4 |
idAnTimeTableA row of this table contains information about the current time on the Analyzer. This table will have only one row. SEQUENCE OF IdAnTimeEntry .1.3.6.1.2.1.1.1.4 |
idAnTimeEntryEntry containing information pertaining to the time an alert was generated. IdAnTimeEntry .1.3.6.1.2.1.1.1.4.1 |
idAnTimeOffsetSpecifies the offset from Coordinated Universal Time UTC, formerly referred to as Greenwich Mean Time, that the idAnTimeDate and idAnTimeTime elements represent.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.4.1.1 |
idAnTimeNtpStampThe NTP timestamp.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.4.1.2 |
idAnTimeDateThe Date.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.4.1.3 |
idAnTimeTimeThe Time.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.4.1.4 |
idClassificationTableEach row of this table contains information about the classification of an alert and is indexed by idAlertID and the idClassification Index. SEQUENCE OF IdClassificationEntry .1.3.6.1.2.1.1.1.5 |
idClassificationEntryEntry containing information pertaining to the classification of the alert. IdClassificationEntry .1.3.6.1.2.1.1.1.5.1 |
idClassificationIndexAn index that uniquely identifies the row in the table.ro INTEGER .1.3.6.1.2.1.1.1.5.1.1 |
idClassificationOriginThe NTP timestamp.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.5.1.2 |
idClassificationNameThe Date.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.5.1.3 |
idClassificationUrlThe Time.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.5.1.4 |
idSourceTableEach row of this table contains information about the source of an attack for which the alert is being raised. SEQUENCE OF IdSourceEntry .1.3.6.1.2.1.1.1.6 |
idSourceEntryEntry pertaining to a source of the attack. IdSourceEntry .1.3.6.1.2.1.1.1.6.1 |
idSourceIndexAn index uniquely identifying the host entry in the table.ro INTEGER .1.3.6.1.2.1.1.1.6.1.1 |
idSourceSpoofedAn indication of whether the analyzer believes this to be the true source of the event.ro Enumeration .1.3.6.1.2.1.1.1.6.1.2 |
idSourceIDAn Identifier for the sourcero SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.6.1.3 |
idTargetTableEach row of this table contains information about the target of the attack for which the alert is being raised. SEQUENCE OF IdTargetEntry .1.3.6.1.2.1.1.1.7 |
idTargetEntryEntry containing information pertaining to the time an alert was generated. IdTargetEntry .1.3.6.1.2.1.1.1.7.1 |
idTargetIndexAn index uniquely identifying the target entry in the table.ro INTEGER .1.3.6.1.2.1.1.1.7.1.1 |
idTargetDecoyAn indication of whether the analyzer believes this to be the true target of the event.ro Enumeration .1.3.6.1.2.1.1.1.7.1.2 |
idTargetIDAn Identifier for the targetro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.7.1.3 |
idToolAlertTableEach row of this table contains information tool used in the attacks. SEQUENCE OF IdToolAlertEntry .1.3.6.1.2.1.1.1.8 |
idToolAlertEntryEntry containing information about the tool which was used in the attack. IdToolAlertEntry .1.3.6.1.2.1.1.1.8.1 |
idToolAlertIDIndexAn index uniquely identifying the entry in the table.ro INTEGER .1.3.6.1.2.1.1.1.8.1.1 |
idToolAlertNameThe name of the tool used in the attack.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.8.1.2 |
idToolAlertCommandThe command or operation the tool was asked to perform.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.8.1.3 |
idToolAlertIDsThe alerts that have been identified as being related to the tool name.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.8.1.4 |
idOverflowAlertTableEach row of this table contains information about the buffer-overflow types of attacks. SEQUENCE OF IdOverflowAlertEntry .1.3.6.1.2.1.1.1.9 |
idOverflowAlertEntryEntry containing buffer-overflow related information for the corresponding attack. IdOverflowAlertEntry .1.3.6.1.2.1.1.1.9.1 |
idOverflowAlertProgramThe program that the overflow attacker attempted to run.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.9.1.1 |
idOverflowAlertSizeThe size, in bytes, of the overflowing buffer.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.9.1.2 |
idOverflowAlertBufferSome or all of the data that was sent to the program.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.9.1.3 |
idCorrelationAlertTableContains the list of alerts(indexed by idCorrelationIndex) which were correlated to generate the present alert (indexed by idAlertID). SEQUENCE OF IdCorrelationAlertEntry .1.3.6.1.2.1.1.1.10 |
idCorrelationAlertEntryOne of the alerts that was used in the correlation to generate the present alert indexed by idAlertID . IdCorrelationAlertEntry .1.3.6.1.2.1.1.1.10.1 |
idCorrelationAlertIndexAn index uniquely identifying the CorrelationAlert entry in the table.ro INTEGER .1.3.6.1.2.1.1.1.10.1.1 |
idCorrelationAlertIDsList of alertIds that are correlated.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.10.1.2 |
idAdditionalDataTableEach row of this table contains additional information related to the alert that is being raised. SEQUENCE OF IdAdditionalDataEntry .1.3.6.1.2.1.1.1.11 |
idAdditionalDataEntryAdditional information corresponding to the alert that has been raised. IdAdditionalDataEntry .1.3.6.1.2.1.1.1.11.1 |
idAdditionalDataIndexAn index that along with the Alert-ID uniquely identifies the row in the table.ro INTEGER .1.3.6.1.2.1.1.1.11.1.1 |
idAdditionalDataTypeThe type of the data in this element.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.11.1.2 |
idAdditionalDataMeaningA string that describes the meaning of the data in this element. These strings will be implementation dependent.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.11.1.3 |
idArgumentsTableEach row of this table contains information about the arguments used in the process indexed by idTargetIndex. SEQUENCE OF IdArgumentsEntry .1.3.6.1.2.1.1.1.12 |
idArgumentsEntryA row containing one element of the argument information. IdArgumentsEntry .1.3.6.1.2.1.1.1.12.1 |
idArgumentsSDTypeAn enumeration of the type of the node on which the referenced process is running .ro Enumeration .1.3.6.1.2.1.1.1.12.1.1 |
idArgumentsProcIndexAn index to identify the process.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.12.1.2 |
idArgumentsThe list of the arguments.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.12.1.3 |
idUserTableThe table containing information about users. . SEQUENCE OF IdUserEntry .1.3.6.1.2.1.1.1.13 |
idUserEntryA row containing the details of a user IdUserEntry .1.3.6.1.2.1.1.1.13.1 |
idUserSDTypeAn enumeration of the type of the node on which the referenced user exists .ro Enumeration .1.3.6.1.2.1.1.1.13.1.1 |
idUserIndexAn index uniquely identifying the user entry in the table.ro INTEGER .1.3.6.1.2.1.1.1.13.1.2 |
idUserIdentThe ID of the user.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.13.1.3 |
idUserNameThe name of the user.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.13.1.4 |
idUserUidThe UID of the user.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.13.1.5 |
idUserGroupThe group of the user.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.13.1.6 |
idUserGidThe gid of the user.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.13.1.7 |
idUserSerialThe serial number of the user.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.13.1.8 |
idProcessTableA Table containing details of processes. SEQUENCE OF IdProcessEntry .1.3.6.1.2.1.1.1.14 |
idProcessEntryEach row contains details of a process indexed by idProcessIndex on a node indexed by idNodeIndex of type given by idProcessSDType related to the alert indexed by idAlertID. IdProcessEntry .1.3.6.1.2.1.1.1.14.1 |
idProcessSDTypeAn enumeration of the type of the node on which the referenced process is running .ro Enumeration .1.3.6.1.2.1.1.1.14.1.1 |
idProcessIndexAn index uniquely identifying the process entry in the table.ro INTEGER .1.3.6.1.2.1.1.1.14.1.2 |
idProcessIDThe ID of the process.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.14.1.3 |
idProcessNameThe name of the process.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.14.1.4 |
idProcessPidThe PID of the process.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.14.1.5 |
idProcessPathThe absolute path of the process.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.14.1.6 |
idAddressTableA Table containing address entries. SEQUENCE OF IdAddressEntry .1.3.6.1.2.1.1.1.15 |
idAddressEntryA row containing the address details. IdAddressEntry .1.3.6.1.2.1.1.1.15.1 |
idAddressTypeAn enumeration of the node type - this may be a source node a destination node or just an analyzer.ro Enumeration .1.3.6.1.2.1.1.1.15.1.1 |
idAddressTypeIndexAn enumeration of the node type - this may be a source node a destination node or just an analyzer.ro Enumeration .1.3.6.1.2.1.1.1.15.1.2 |
idAddressIndexAn index uniquely identifying the node entry in the table.ro INTEGER .1.3.6.1.2.1.1.1.15.1.3 |
idAddressIDAn Identifier for the nodero SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.15.1.4 |
idAddressCategoryA category for the nodero SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.15.1.5 |
idAddressAddressThe address.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.15.1.6 |
idAddressNetmaskThe mask of the address.ro IpAddress .1.3.6.1.2.1.1.1.15.1.7 |
idNodeTableA table containing details of nodes related to alerts. SEQUENCE OF IdNodeEntry .1.3.6.1.2.1.1.1.16 |
idNodeEntryA row pertaining to one node IdNodeEntry .1.3.6.1.2.1.1.1.16.1 |
idNodeIndexTypeAn enumeration of the node type - this may be a source node a destination node or just an analyzer.ro Enumeration .1.3.6.1.2.1.1.1.16.1.1 |
idNodeIndexAn index uniquely identifying the node entry in the table.ro INTEGER .1.3.6.1.2.1.1.1.16.1.2 |
idNodeIDAn Identifier for the nodero SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.16.1.3 |
idNodeCategoryAn category for the nodero SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.16.1.4 |
idNodeNameAn name for the nodero SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.16.1.5 |
idNodeLocationThe location of the nodero SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.16.1.6 |
idAnalyzerTableA table containing the list of analyzers serviced by this MIB. SEQUENCE OF IdAnalyzerEntry .1.3.6.1.2.1.1.1.17 |
idAnalyzerEntryA row containing details of an Analyzer IdAnalyzerEntry .1.3.6.1.2.1.1.1.17.1 |
idAnalyzerIndexAn Index to uniquely identify the Analyzer in this table.ro INTEGER .1.3.6.1.2.1.1.1.17.1.1 |
idAnalyzerIDAn identifier to uniquely identify the Analyzer in the domain.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.17.1.2 |
idAnalyzerNodeIndexAn Index pointing to the corresponding Node in the Node Table.ro INTEGER .1.3.6.1.2.1.1.1.17.1.3 |
idAnalyzerProcessIndexAn Index pointing to the corresponding process in the process table.ro INTEGER .1.3.6.1.2.1.1.1.17.1.4 |
idEnvironmentTableEach row of this table contains information about the environment variables used in the process indexed by idTargetIndex. SEQUENCE OF IdEnvironmentEntry .1.3.6.1.2.1.1.1.18 |
idEnvironmentEntry. IdEnvironmentEntry .1.3.6.1.2.1.1.1.18.1 |
idEnvironmentIndexAn index uniquely identifying the process entry in the table.ro INTEGER .1.3.6.1.2.1.1.1.18.1.2 |
idEnvironmentThe ID of the process.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.18.1.3 |
idServiceTableEach row of this table contains information about the services that have been targeted.. SEQUENCE OF IdServiceEntry .1.3.6.1.2.1.1.1.19 |
idServiceEntry. IdServiceEntry .1.3.6.1.2.1.1.1.19.1 |
idServiceIndexAn index uniquely identifying the process entry in the table.ro INTEGER .1.3.6.1.2.1.1.1.19.1.1 |
idServiceIDThe ID of the service.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.19.1.2 |
idServiceNameThe name of the service.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.19.1.3 |
idServiceDportThe list of destination ports.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.19.1.4 |
idServiceSportThe list of source ports.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.19.1.5 |
idServiceProtocolThe protocol used by the service.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.19.1.6 |
idServicePortListThe list of service related ports.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.2.1.1.1.19.1.7 |