Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
alexwoolford
New Contributor

CEF proto: string or integer?

The common event format (CEF) was created by a company called ArcSight, who were acquired by HP. According to docs on HP's website (search for a file called "CommonEventFormatV24.pdf") the protocol property is defined as:

[ul]
  • CEF key name: proto
  • full name: transportProtocol
  • data type: String
  • length: 31
  • meaning: Identifies the Layer-4 protocol used. The possible values are procols such as TCP or UDP.[/ul]

    In the Fortinet docs, the protocol is an integer:

    [ul]
  • log field name: proto
  • description: Protocol number
  • data type: uint
  • length: 3[/ul]

     

    Since CEF is a standard, there should be no ambiguity. Does anyone know if proto should be a string or an integer?

  • 0 REPLIES 0
    Labels
    Top Kudoed Authors