The ~id alias is a generic term for referencing all keywords that contain some type of ID. ~id references such keywords as:
| Class ID for event collection |
| Specific event identifier |
| Numerical representation of a protocol (6=TCP, 17=UDP, 47=GRE, and so on) |
| Specific connection identifier |
| Specific transaction identifier |
| Specific session identifier |
| Specific device identifier |
| Specific agent identifier |
| Specific account identifier |
| Used when a given user (such as |
| Specific group identifier |
| Specific policy identifier |
| Specific port ID or terminal port ID |
| Specific process ID, typically used for application PIDs |
| Specific parent process ID, typically used for application PPIDs |
| Rule or Signature ID containing a unique ID for a given rule or signature |
| Specific reference ID relating two or more things together |
| Specific request ID, specifying the identifier of a given request |
| Specific call identifier |
| Specific handle identifier, referring to process handle IDs |
| Specific operation identifier |
| User ID of a remote calling identity, typically observed in Windows event logs as calling ID |
| Common Vulnerabilities and Exposures identifier, can be referenced by either reference number or year |
| Specific process identifier |
| Specific creator process identifier |
| Specific thread identifier |
| Specific station identifier |
| Specific file identifier |
| Specific parent file identifier. In Bro logs, this is the identifier associated with a container file from which the child ( |
| Sent file identifier, found in Bro http logs as the |
| Received file identifier, found in Bro http logs as the |
| In Bro ssl logs, the |
For example:
~id:CrGQK52UXAI2JQL1r9