What is our primary use case?
I implemented Fortinet FortiSIEM in my company to collect all logs from old systems, networks, and security devices in the network. Fortinet FortiSIEM has a correlation rule, and from it, you can generate incidents and get analytics. The tool also serves as a threat intelligence and integration platform. With FortiGuard or any third-party tools, Fortinet FortiSIEM, as a threat intelligence platform, can enrich the log attributes or criteria, which is well reflected in incidents.
What is most valuable?
The most valuable feature of the solution for the detection of threats stems from FortiSIEM's components, including the threat intelligence platform and the ability to provide integrations.
What needs improvement?
Fortinet FortiSIEM is a better solution than other products. As a SIEM solution, it can meet all the requirements of customers.
The product already offers good integration capabilities with multiple vendors. There will be new products being introduced every day in the market, so Fortinet FortiSIEM needs to ensure integrations are possible with the new tools. Fortinet FortiSIEM needs to provide better API integrations to users. Better support services can help you deal with the integration party easily. API integration capabilities will make it easy to integrate Fortinet FortiSIEM with new products unless such tools have custom or special configurations set by the vendor or the device.
For how long have I used the solution?
I have been using Fortinet FortiSIEM since 2018.
What do I think about the stability of the solution?
Stability-wise, I rate the solution a nine out of ten.
If every device can get a ten out of ten in terms of stability, then I believe it is a 100 percent perfect product.
What do I think about the scalability of the solution?
It is an easily scalable solution. Suppose you want to increase the scalability in seconds. You can increase the number of tools with an HA supervisor to handle multiple events per second, and you can use multiple collectors for remote defense. It is easy to manage the tool's scalability and availability.
My company deals with around six customers who use the product.
How are customer service and support?
The solution's technical support is good. If you want to deal with the issues from the tool of other vendors, Fortinet's support team provides help.
How was the initial setup?
The product's initial setup phase is easy.
In Fortinet FortiSIEM, with multiple tenants, one does not need to invest in the implementation process.
After the virtual machine deployment or hardware appliance initial configuration, I think network discovery is the first step in the installation process. The process continues with vendor discovery and asset inventory at customer sites. Three intelligence integrations are the second step, and the configuration with the customer's devices to send all logs to SNMP TRAPS and then to the SIEM solution is a part of the main basic implementation. If you have some configurations and event handler and event order and logs, the initial configuration can be managed depending on the needs of customers.
What's my experience with pricing, setup cost, and licensing?
I don't have the price list of any of the competitors of Fortinet FortiSIEM. I work with the technical part of the tool.
There is a need to make yearly payments towards the licensing charges attached to the product. The free version license of the product is available for two months.
What other advice do I have?
The product offers multiple integrations with all vendors. If there is a new or unknown vendor in the market, a custom API can be made to ensure that integration with Fortinet FortiSIEM is possible.
I rate the integration capabilities of the tool a nine out of ten.
The implementation of the product can improve incident response time according to the arrangement and local relation of built-in rules or custom rules. This will reduce the time of incident response, especially if you use a SOAR solution with it. You can enrich the tool by buying a SOAR solution.
It is a good product in general. It is a product that offers stability and scalability with a multiple and wide range of built-in rules. The solution is also easy to use.
I rate the tool a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator