Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ryan_Kang
New Contributor

What does "bid" in FortiOS log fields represent?

I found the bid in the FortiOS log field.

I'm not sure what this field means.

who can tell me?

 

The log format documentation doesn't even mention the bid field.




I am the center of the world
SmileStory ^0^
I am the center of the worldSmileStory ^0^
1 Solution
Debbie_FTNT

Hey Ryan,

thanks for sharing the logs :).

There are some fields FortiAnalyzer adds when adding the logs to its database, as basically meta-information, like itime and date/time fields - one is the timestamp from when FortiGate wrote the message, the other is when FortiAnalyzer received the message.

If I remember correctly, dstower, dvid, epid, and bid reference other tables in FortiAuthenticator database with added information (dvid is device ID for example, the reference for this particular FortiGate in FortiAnalyzer device table).

I can't recall what bid exactly references, and haven't been able to find this internally, my apologies.

 

Edit: If you download the log from FortiGate directly, it should not contain the bid/dvid/epid/etc fields.

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++

View solution in original post

4 REPLIES 4
akristof
Staff
Staff

Hello,

 

Can you please tell me in which log you can see this field and which FOS version?

Adrian
Ryan_Kang

Dear. Debbie

 

 

Thank you for the reply.

 

I try to understand it as a log field that is internally required for Fortinet product integration.

 

Thank you again




I am the center of the world
SmileStory ^0^
I am the center of the worldSmileStory ^0^
Ryan_Kang

Currently, FGT is using version 6.2.10.

The log below is the FGT log collected by FAZ.
FAZ version is 6.4.7.

 

Some of the log fields below cannot be found on Log Message Reference Document.


itime=1641740348 date="2022-01-09" time="23:59:07" devid="FG1K" vd="10G" type="traffic" subtype="forward" action="start" app="HTTPS" appcat="unscanned" bid=29122009 devname="Network-FW" dstcountry="Japan" dstepid=101 dsteuid=3 dstintf="port33" dstintfrole="undefined" dstip="52.114.36.17" dstowner="501" dstport=443 duration=0 dvid=1043 epid=101 euid=3 eventtime=1641740347 id=7051221103183661695 level="notice" logid="0000000015" logver=600060272 policyid=2 policytype="policy" poluuid="ce8b6fb2-8516-51e6-3f31-6c762b2920c1" proto=6 rcvdbyte=0 sentbyte=0 sentpkt=0 service="HTTPS" sessionid=1815591154 srccountry="Korea, Republic of" srcintf="port34" srcintfrole="undefined" srcip="210." srcport=50885 trandisp="noop"

 




I am the center of the world
SmileStory ^0^
I am the center of the worldSmileStory ^0^
Debbie_FTNT

Hey Ryan,

thanks for sharing the logs :).

There are some fields FortiAnalyzer adds when adding the logs to its database, as basically meta-information, like itime and date/time fields - one is the timestamp from when FortiGate wrote the message, the other is when FortiAnalyzer received the message.

If I remember correctly, dstower, dvid, epid, and bid reference other tables in FortiAuthenticator database with added information (dvid is device ID for example, the reference for this particular FortiGate in FortiAnalyzer device table).

I can't recall what bid exactly references, and haven't been able to find this internally, my apologies.

 

Edit: If you download the log from FortiGate directly, it should not contain the bid/dvid/epid/etc fields.

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
Labels
Top Kudoed Authors