What is our primary use case?
We use this technology to configure and setup rules and conduct threat hunting.
How has it helped my organization?
Connecting all supported security technologies, such as firewalls from Palo Alto, Fortinet, and Check Point, is crucial. The platform needs to recognize logs coming from sources like Syslog. You might integrate an IPS or WAF for use cases like phishing. Whether on-premise or in the cloud, AD is especially important for providing context and supporting specific use cases. If FortiSIEM doesn't natively support a particular technology or cannot parse certain security logs, you can configure a custom parser to interpret those logs effectively.
What is most valuable?
It is used in analytics, providing powerful tools to obtain specific information. For instance, if you detect a potential OS DDoS attack, you can quickly search for detailed information about that threat. With features like threat hunting, you can query specific IP addresses and access extensive data.
Additionally, FortiSIEM allows you to match IPs with threat intelligence feeds from sources like Kaspersky or Anomali, adding valuable context. The platform also simplifies rule configuration, making setting up rules for specific use cases easy and highlighting its effectiveness as a robust security solution.
What needs improvement?
When an alert triggers in Fortinet FortiSIEM, the layout or format can feel limited; the template you configure for alerts offers only a few specific fields, which can be restrictive. It would be much better if the technology supported more fields or allowed for greater customization, making it more versatile for managers to tailor alerts according to their specific use cases. This limitation is a weakness of the platform.
For how long have I used the solution?
I have been using Fortinet FortiSIEM as a partner for two years.
What do I think about the scalability of the solution?
600 users are using this solution.
To effectively plan for the future, it's important to anticipate how much the organization will grow. Considering Fortinet's MSSP model, you need to estimate how many clients you'll acquire and how much your client base might expand. For a single organization, it's crucial to understand how many users you'll be adding during that period to ensure the system can scale accordingly.
How are customer service and support?
Support responds very slowly.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I have used ArcSight. Fortinet stands out because it supports a broader range of technologies, allowing for greater integration within a system. Another key advantage is its robust analytics, making it easier to obtain specific information consistently.
How was the initial setup?
The initial setup is easy. If you want to deploy FortiSIEM on-premise, you need to purchase a specific appliance or install it on your hardware. I have deployed FortiSIEM both on-premise and in the cloud, managing both environments effectively.
Deployment depends on the architecture since FortiSIEM uses various components, such as the supervisor, event collector, and worker. It can be set up in just one day if you're deploying it as an all-in-one solution.
What about the implementation team?
I did the deployment alone.
What's my experience with pricing, setup cost, and licensing?
What other advice do I have?
Maintenance depends on the number of log sources configured and the overall architecture. The system's load must be considered to monitor all components and handle upgrades or fix specific features. Managing the system typically requires just a couple of people for an all-in-one deployment with around ten to twenty log sources.
Overall, I rate the solution a seven out of ten.
*Disclosure: My company has a business relationship with this vendor other than being a customer: Partner