I primarily use FortiSIEM for Rwandan clients in banking and finance. Most of my clients require strictly on-prem solutions because of national data regulations. They are also skeptical of putting their data on the cloud, and the law requires all data to reside at a domestic data center.
Cyber Security Specialist at EAST-NB
It integrates well with solutions by the same vendor and other popular third-party vendors
Pros and Cons
- "I like FortiSIEM because it integrates natively with our other Fortinet solutions and the Fortinet Fabric, but it also integrates with Cisco, Palo Alto and other security fabrics."
- "The only drawback is the licensing model. It can get expensive if you want to integrate more solutions."
What is our primary use case?
What is most valuable?
I like FortiSIEM because it integrates natively with our other Fortinet solutions and the Fortinet Fabric, but it also integrates with Cisco, Palo Alto and other security fabrics.
What needs improvement?
The only drawback is the licensing model. It can get expensive if you want to integrate more solutions.
What do I think about the stability of the solution?
I rate FortiSIEM eight out of 10 for stability.
Buyer's Guide
Fortinet FortiSIEM
November 2024
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
814,649 professionals have used our research since 2012.
What do I think about the scalability of the solution?
FortiSIEM is highly scalable, but you need to consider the costs. It will be expensive if you want to scale it up.
How are customer service and support?
We rely on Fortinet support, and their response times have room for improvement. They can take a while to respond sometimes.
How was the initial setup?
Setting up FortiSIEM is straightforward because they provide you with a step-by-step guide that covers installation and troubleshooting. The deployment time depends on your setup and what you need to integrate. It can take days or weeks, but we can typically finish in under a week.
There isn't a single one-size-fits-all implementation because some clients have mixed environments, and we need to develop a custom solution if we are working on multiple fabrics.
What's my experience with pricing, setup cost, and licensing?
You can get an annual license for FortiSIEM or a three-year license. It can be expensive if you're pulling data from many sources. If you plan to keep the solution for a while, I recommend choosing a three-year license or longer to save money.
What other advice do I have?
I rate FortiSIEM eight out of 10. My only advice is to understand your environment and learn as much as you can about SIEM before implementing the solution. I started by building open-source solutions from scratch, which gave me a big picture view of how to implement SIEM solutions and work with fabrics. You need to learn the basics about how to set rules and interpret logs.
Disclosure: My company has a business relationship with this vendor other than being a customer: Implementer
Network administrator at a manufacturing company with 51-200 employees
It offers a complete analysis of the environment, but it is expensive
Pros and Cons
- "The tool's most valuable feature stems from the fact that I can see a complete analysis, like all the incidents that have happened, and it detects everything in real-time."
- "The solution's technical support didn't help our company a lot."
What is our primary use case?
I use the solution in my company for our client, which is a big university in Tunisia, and they have many servers and virtual machines. The university has to prevent attacks by making sure that they can stop the attack at the beginning. Fortinet is good for knowing if any of the equipment in the network has been attacked like ransomware or something, and we can stop the attack and secure the network.
What is most valuable?
The tool's most valuable feature stems from the fact that I can see a complete analysis, like all the incidents that have happened, and it detects everything in real-time. It lets you know of the attack in real-time. The tool sends alerts and reports, so I think it is a useful tool.
What needs improvement?
There is a port in Fortinet FortiSIEM. If something happens, you have to enter events and create a rule to stop the attack, which I think needs to be made automatic. If any incident occurs, I hope that Fortinet FortiSIEM does the work automatically without the intervention of a human or an IT admin.
I don't want to create a rule to stop an attack. Lately, many people have been trying to access the VPN, and they are not even registered with our firewall. The team detects issues but doesn't do anything. I have to create a rule to include the addresses and details of the people who want to access the VPN in the block list, but I want the tool to do all this without me.
For how long have I used the solution?
I have been using Fortinet FortiSIEM for two months. My company has a partnership with the solution.
What do I think about the stability of the solution?
It is a stable solution.
What do I think about the scalability of the solution?
The tool is scalable enough to do what you really want.
My clients run big businesses.
How are customer service and support?
The solution's technical support didn't help our company a lot. When it came to Fortinet FortiSIEM, we added the devices, and started making rules, but when we asked a question to the tool's support team, it took them a long time to answer. I rate the technical support a five out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
At the beginning the product's initial setup phase was complex. Lately, since I have started to understand the tool, the setup phase has become easy.
The solution is deployed on an on-premises model with VMs in a local data center.
The solution can be deployed in four days. One day is for installing the VMs, one day is for understanding the tool's dashboard and its rules, one day is for installing the agents and adding the equipment, and one day is for seeing what the clients want exactly.
What's my experience with pricing, setup cost, and licensing?
The tool is really expensive. For what the tool does for our team, the price is fair.
What other advice do I have?
As my company did not fully complete everything, the installation is not stable 100 percent.
In terms of Fortinet FortiSIEM's uptime and system stability, the tool can do detection in real-time. I think it is available for users all the time.
Those who have many servers and equipment can use SIEM so they can manage. It helps a person to see what equipment has incidents and how to prevent an attack before it happens. You can't manage much equipment, like 15 VMs or servers, by yourself. You need solutions to do that and give you alerts if anything happens.
As the product is not automated enough, I rate the tool a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Last updated: Sep 5, 2024
Flag as inappropriateBuyer's Guide
Fortinet FortiSIEM
November 2024
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
814,649 professionals have used our research since 2012.
Solution Consultant at 1&1 Versatel Deutschland GmbH
It's a good tool for making security processes transparent
Pros and Cons
- "FortiSIEM is a great tool for making security processes transparent."
What is our primary use case?
FortiSIEM combines information from operations and integrates it into management.
What is most valuable?
FortiSIEM is a great tool for making security processes transparent.
What do I think about the stability of the solution?
I rate FortiSIEM 10 out of 10 for stability.
What do I think about the scalability of the solution?
I rate FortiSIEM nine out of 10 for scalability.
How was the initial setup?
Setting up FortiSIEM is straightforward. I prefer this product in the Fortinet environment. It's easy to install and configure.
What's my experience with pricing, setup cost, and licensing?
FortiSIEM might be considered expensive in some markets. We have an international customer base, and it's affordable for a lot of them.
However, customers in some markets cannot build a suitable use case around it. But it's not because of the product. It often depends on customers' operation organization.
You also need some operation and security knowledge to make a professional management decision.
A company needs to work with the consultants and distributors who are delivering the environment and necessary support.
What other advice do I have?
I rate Fortinet FortiSIEM nine out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
A scalable product that offers good UI and firewall
Pros and Cons
- "The product's initial setup phase was easy."
- "The stability of the product is an area of concern where improvements are required."
What is our primary use case?
I use the solution in my company since it provides ease of monitoring. My company uses the product to get reports for our customers and monitoring purposes, as per the customer's preferences.
What needs improvement?
At times, I have noticed that Fortinet FortiSIEM suddenly goes down, and because of this, I have to reboot the servers from the engineers. Usually, I have to restart the panel again to get the product functioning. The aforementioned area of concern has been around for a very long time, making it something where improvements are required.
The stability of the product is an area of concern where improvements are required.
ArcSight can provide a detailed report for a year in a PDF format. In Fortinet FortiSIEM, there is a need to put in manual effort to get a detailed report. In Fortinet FortiSIEM, if I get reports for a specific time frame, I have to manually narrow them down by myself, after which I will not be able to get them in a Word or PDF format, which can be challenging.
For how long have I used the solution?
I have been using Fortinet FortiSIEM for a year. My company uses the product for some of our internal purposes.
What do I think about the scalability of the solution?
It is a scalable tool. The product can handle a considerable number of customers.
At the moment, there are only two people in my company who use the solution. In the future, the number of uses may increase, especially if my company has to deal with more customers who want to use Fortinet FortiSIEM.
How are customer service and support?
Based on what I heard from my colleagues, the technical support is not bad. My colleagues directly contact the technical support for help.
How was the initial setup?
The product's initial setup phase was easy. I wasn't a part of the deployment process.
What other advice do I have?
In terms of how the tool supports our company's compliance monitoring and reporting practices, I would say that it stems from the fact that Fortinet FortiSIEM is able to serve what our company's customers want while also having the ability to offer solutions, making it quite easy for us to give the customers what they want. The fact that the solution helps my company provide the reports that my customer wants is actually nice. The tool also offers customization ability.
The features of Fortinet FortiSIEM that I find most effective for real-time security event correlation are real-time server connections, which allow me to see all the servers that are online at a particular period of time. The product also shows the threats and bifurcates them into high, medium, and low. The solution has the ability to generate reports easily. The product also provides specific solutions for any threats that are found.
The way Fortinet FortiSIEM improves my company's security posture stems from the fact that with the tool, I can see whatever is happening in real-time. In terms of security issues, if I try to see the problem or threat, then I can really dig deep into what is happening, which is a nice feature.
The tool is easy to maintain. Only two people are required to maintain the solution.
If I compare the integration capabilities of ArcSight with Fortinet FortiSIEM, I would have to say that the latter is in a better position to provide its customers with more details in terms of cybersecurity threats or if they want to compare the firewalls. Fortinet FortiSIEM is better for customers with no cybersecurity knowledge since it helps them understand the product. Fortinet FortiSIEM is better for the security of its customers.
I would ask those who plan to use the Fortinet FortiSIEM to see whether there are other solutions with which it needs to interact in their environment. Fortinet FortiSIEM is one of the best solutions I have dealt with, considering that it has a nice user interface. The update page is good and works in real time. The firewall part of the tool is good. I don't think there is anything that can cause problems for the tool's firewall. I actually liked the tool's firewall.
I rate the overall tool a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT Security & CyberSecurity Consultant at digitalDefense Information Systems GmbH
A scalable solution with extensive customization options
Pros and Cons
- "This solution offers extensive customization options, making it possible to adapt it precisely to their requirements."
- "Customer support service could be better."
What is our primary use case?
If a customer is looking to establish a centralized monitoring and security solution, Fortinet FortiSIEM can be tailored to meet their specific needs effectively. This solution offers extensive customization options, making it possible to adapt it precisely to their requirements.
What is most valuable?
It works exceptionally well when combined with a vulnerability management solution.
What needs improvement?
Customer support service could be better.
What do I think about the stability of the solution?
It provides great stability features.
What do I think about the scalability of the solution?
Scalability is excellent, especially for our enterprise-level clients.
How are customer service and support?
I have moderate satisfaction with customer support, and we've learned to manage it adequately. I would rate it three out of ten.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
I previously worked with LogPoint, which had rigid pricing structures. In contrast, we value flexibility and aim to provide more adaptable support, so we switched to Fortinet FortiSIEM.
How was the initial setup?
The initial setup is quite swift.
What about the implementation team?
The deployment process usually takes just one to two days to have the basics up and running. This involves connecting the collectors and configuring the systems.
What's my experience with pricing, setup cost, and licensing?
Pricing is determined based on the customer's budget. We discuss how to tailor the pricing to fit the specific needs and financial considerations of the customer.
What other advice do I have?
I would highly recommend it. It's a top-tier solution, receiving a solid ten out of ten rating.
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Asst Programmer Data Center at a consultancy with 10,001+ employees
Lacks a level of support we'd expect to see, particularly for patching; Threat Hunting is a great feature
Pros and Cons
- "The Threat Hunting feature provides complete traffic analysis."
- "Patching is not great - we're not getting the support we'd expect."
What is our primary use case?
Our use case is for collecting logs and monitoring internet traffic through firewalls. We have Fortinet firewalls and Fortinet WAF. I'm a system programmer and we are customers of Fortinet.
What is most valuable?
I like the Threat Hunting feature which provides complete traffic analysis, like file movement and processes. It's a good feature.
What needs improvement?
We have recently faced many issues in terms of support and their turnaround time for giving support as well as their patch level. The patching is one of the significant issues we face with Fortinet SIEM. We're at the enterprise level and we're not getting the support we'd expect. They really need to bring in new features like proper dashboards and alert systems and a real-time alert system which would be beneficial for users.
For how long have I used the solution?
I've been using this solution for four years.
What do I think about the scalability of the solution?
Scalability is good; you just add extra licenses. We have 15 admin users and around 10,000 EPS.
How was the initial setup?
There are lots of issues with licensing policies like the agentless and agent-based installation. It creates a lot of issues because when we purchase the SIEM, by default, we expect most of the licenses to be in the bundle. But it's not like that. We need to purchase separate licenses for each agent and agentless system. There is also licensing with the EPS. It's quite difficult for proposing and purchasing the solution. We hire Fortinet professional services for deployment.
Which other solutions did I evaluate?
I think that QRadar and RSE are better solutions than SIEM. The interactivity, scalability, and performance are far better than Fortinet.
What other advice do I have?
My needs are not getting met with this solution so I would not recommend it to anyone and rate it four out of 10.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Research Associate at a comms service provider with 1,001-5,000 employees
Good solution for security detection and response
Pros and Cons
- "Our customer did not have security monitoring in the first place. With this solution, it provided security posture management and visibility about the security landscape and threats that they had."
- "The product does not have Security Orchestration and Automation Response, I would recommend adding this feature."
What is our primary use case?
My company is a partner of Fortinet FortiSIEM. We are a service provider and I take the solution from Fortinet and deploy it for my customers. We use the solution for security detection and response. This is a customer based solution, our customer's security admins and security operations use the solution, compromised of a team between three to five people.
How has it helped my organization?
Our customer did not have security monitoring in the first place. With this solution, it provided security posture management and visibility about the security landscape and threats that they had.
What is most valuable?
Fortinet FortiSIEM combines the SOC and NOC into a single solution with a single pane of glass. This feature on its own is next level and its easy to handle.
What needs improvement?
Fortinet FortiSIEM should consider converting the purchase model from a CapEX investment into a pay-per-use model. By doing this, it will be more attractive for more customers.
The product does not have Security Orchestration and Automation Response, I would recommend adding this feature.
For how long have I used the solution?
I have been using Fortinet FortiSIEM for two years.
What do I think about the stability of the solution?
Stability is very good.
What do I think about the scalability of the solution?
Fortinet FortiSIEM is scalable.
How are customer service and support?
Technical support is perfect.
How was the initial setup?
The initial setup of Fortinet FortiSIEM was easy. The deployment took a week and a half and was based on a project plan. You don't need more than two people to deploy and maintain this solution.
What about the implementation team?
We use an integrator for the deployment of Fortinet FortiSIEM.
What's my experience with pricing, setup cost, and licensing?
The price of Fortinet FortiSIEM is manageable. The cost is approximately $90,000 on an annual basis.
What other advice do I have?
Before fitting the product into your environment, make sure you have the right requirements.
I would rate Fortinet FortiSIEM a 9 out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Asst Programmer Data Center at a consultancy with 10,001+ employees
Plenty of features, reliable, but more frequent updates needed
Pros and Cons
- "We have found the most important features in Fortinet FortiSIEM to be the correlation, file utility check, latest file, and hash changes. These features are important for us."
- "We expect the latest patch from Fortinet FortiSIEM to give the ability to work with signature files."
What is our primary use case?
We are creating our new dashboards and correlations as per our requirements with Fortinet FortiSIEM.
What is most valuable?
We have found the most important features in Fortinet FortiSIEM to be the correlation, file utility check, latest file, and hash changes. These features are important for us.
What needs improvement?
We expect the latest patch from Fortinet FortiSIEM to give the ability to work with signature files.
The patch management on the software needs to be better. We have not received frequent updates from their site. That's the major challenge for us. Going by the latest trends there are lots of cyber attacks happening in the entire world. All of the latest trends, patches, file updates, and hash updates should be released as soon as possible, whilst an attack is detected the patch has to be released on time.
For how long have I used the solution?
I have been using Fortinet FortiSIEM for two and a half years.
What do I think about the stability of the solution?
It's a foolproof solution for our requirements, it is stable.
What do I think about the scalability of the solution?
The solution is scalable. However, this depends on the license we purchase. Additionally, to scale the solution requires a large investment for computer hardware, such as SSD, memory, and CPUs.
We have approximately 25 security engineers using the solution and approximately 10,000 end users.
We do not have plans to increase the usage of the solution at this time.
How are customer service and support?
I would rate the support of Fortinet FortiSIEM a four out of ten.
Which solution did I use previously and why did I switch?
We previously were using the Juniper STRM, but Juniper STRM is currently not available. I think that their company was taken over by IBM QRadar, this is why we have gone with FortiSIEM.
How was the initial setup?
The workload required for this software is a major challenge. It requires a huge workload in terms of CPU and memory. It requires a huge workload for the installation and for the integration with all the systems. The whole implementation took approximately six months.
What about the implementation team?
We had help from the Fortinet team for the implementation team.
What was our ROI?
We have received a return on investment by using this solution.
What's my experience with pricing, setup cost, and licensing?
The price of Fortinet FortiSIEM is a lot less when compared to other solutions.
What other advice do I have?
My advice to others thinking about implementing this solution is if your organizational budget is low, then we go for Fortinet FortiSIEM. Otherwise, if we have enough budget, I would recommend IBM QRadar and or other solutions.
I rate Fortinet FortiSIEM a six out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: November 2024
Product Categories
Security Information and Event Management (SIEM)Popular Comparisons
Splunk Enterprise Security
Microsoft Sentinel
Microsoft Defender XDR
IBM Security QRadar
Elastic Security
SolarWinds NPM
PRTG Network Monitor
AWS Security Hub
LogRhythm SIEM
Cisco Secure Network Analytics
ThousandEyes
Nagios XI
Sumo Logic Security
Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- What Questions Should I Ask Before Buying SIEM?
- RSA-EMC vs. other SIEM products?
- What are the pros and cons of internal SOC vs SOC-as-a-Service?
- Between AlienVault and LogRhythm, which solution is suitable for Banks in Gulf Region