~id

Prev Next

The ~id alias is a generic term for referencing all keywords that contain some type of ID. ~id references such keywords as:

classid

Class ID for event collection

eventid

Specific event identifier

protoid

Numerical representation of a protocol (6=TCP, 17=UDP, 47=GRE, and so on)

connectionid

Specific connection identifier

transactionid

Specific transaction identifier

sessionid

Specific session identifier

deviceid

Specific device identifier

agentid

Specific agent identifier

accountid

Specific account identifier

uid

Used when a given user (such as joesample) also has a unique user ID or GUID (such as 9473)

gid

Specific group identifier

policyid

Specific policy identifier

portid

Specific port ID or terminal port ID

pid

Specific process ID, typically used for application PIDs

ppid

Specific parent process ID, typically used for application PPIDs

ruleid

Rule or Signature ID containing a unique ID for a given rule or signature

referenceid

Specific reference ID relating two or more things together

requestid

Specific request ID, specifying the identifier of a given request

callid

Specific call identifier

handleid

Specific handle identifier, referring to process handle IDs

operationid

Specific operation identifier

callinguid

User ID of a remote calling identity, typically observed in Windows event logs as calling ID

cveid

Common Vulnerabilities and Exposures identifier, can be referenced by either reference number or year

processid

Specific process identifier

creatorprocessid

Specific creator process identifier

threadid

Specific thread identifier

stationid

Specific station identifier

fileid

Specific file identifier

parentfileid

Specific parent file identifier. In Bro logs, this is the identifier associated with a container file from which the child (fileid) was extracted as part of the file analysis.

sentfileid

Sent file identifier, found in Bro http logs as the orig_fuids value, indicates the file identifier of a file pertaining to an originator.

rcvdfileid

Received file identifier, found in Bro http logs as the resp_fuids value, indicates the file identifier of a file pertaining to a receiver.

lastalertid

In Bro ssl logs, the last_alert field is the last alert that was seen during the connection.

For example:

~id:CrGQK52UXAI2JQL1r9