We use Fortinet FortiSIEM for storage of security information and analysis, as well as for alerts from the 50-60 services that we have. All of our webs are linked to FortiSIEM. It's a form of SOC tool and data is used for identifying trends and what's happening around the networks. We're customers and end-to-end users when it comes to FortiSIEM, but for other Fortinet products we're either partners or a value-added reseller. I'm the principal cloud architect in our company.
Principal Cloud Architect at Viria Security Oy
Very easy alert setup; a good tool for analysis and for SOC
Pros and Cons
- "Easy alert setup which enables different alerts in different categories."
- "Not very good on non-API features, lacks that functionality."
What is our primary use case?
What is most valuable?
I think the most valuable feature is the easy alert setup, it's very important. It's quite simple to use and enables us to have different alerts in different categories. SOC is able to see all the red alerts, it's impossible to miss them. It's a good tool for analysis and for SOC. We upload all network detection tools that support FortiSIEM and can investigate for different alerts or vulnerabilities. A great feature is that you can use Python scripting for data stack. It's great for devices that don't generate a genuine local source of information.
What needs improvement?
This solution is not very good on non-API features and lacks that functionality. We've raised multiple tickets to Fortinet about this and they are pending there. The product development hasn't been fast enough to ensure it can function on the cloud. It's excellent when you download and get the security locks but in areas like Microsoft 365, you have to fetch the security access using APIs and they don't update quickly enough. If Microsoft announces a new service today, we have to wait at least six months before FortiSIEM start supporting it. It's crucial that the API support is updated, for now FortiSIEM lacks functionality compared to its competitors.
For how long have I used the solution?
Buyer's Guide
Fortinet FortiSIEM
November 2024
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
814,649 professionals have used our research since 2012.
What do I think about the stability of the solution?
It's a very reliable solution, we haven't had any outages during the last year and we're using it a lot. We have over 40 people using it 24/7.
What do I think about the scalability of the solution?
This solution is not very scalable if you have a lot of security events; it's focused more around smaller companies. We've become too big for it with 48,000 devices which we are monitoring and we had to create another instance and split things. It's not perfect because it requires purchase of a second license. We use the solution all the time.
How are customer service and support?
Fortinet support is very fast. If I need to ask something, I'll get a response within a couple of hours.
How was the initial setup?
The initial setup was quite straightforward. They have good documentation and once we deployed, there were only a couple of times where we needed a little bit of support because there were delayed reactions.
What's my experience with pricing, setup cost, and licensing?
The licensing is on an annual basis and calculated on the set up number. Of course, the licensing cost could be less but it's not too bad and is quite nicely priced. With Centreon or Splunk you just pay for the use but if we compare the cost of FortiSIEM with Splunk, it's less than half the price.
Which other solutions did I evaluate?
We took a look at IBM QRadar, which was the main competitor, and we also looked at Splunk. Splunk lost out quickly because of the cost and we ended up going with Fortinet because it was much easier to manage and implement things than QRadar and it has the Python scripting.
What other advice do I have?
If your use case suits this solution, I would recommend it. If you are a professional operator and you're into pre-investing, and not just paying per use, then FortiSIEM is one of the best options you can have.
I rate this product an eight out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
CCO at Oduma Solutions Ltd
Effective multi-tenancy, helpful support, but interface could improve
Pros and Cons
- "Fortinet FortiSIEM's most valuable feature is the simplicity in handling multi-tenancy and the ability to switch between different clients at the same time. That was handled flawlessly."
- "The interface needs some improvements because it's a bit cumbersome when you're trying to view items. It takes some time to get used to. Additionally, sometimes the scrolling does not work."
What is our primary use case?
We are using Fortinet FortiSIEM for multi-tenant SOC service.
Fortinet FortiSIEM is deployed in our data center, and we have one collector. Each client has a collector within their environment. We set up a collector within each client's environment, and then have a VPN connection from the client's environment to our environment.
How has it helped my organization?
Fortinet FortiSIEM has helped us achieve our goal of serving multi-tenant SOC services. We're able to serve multiple clients at the same time.
What is most valuable?
Fortinet FortiSIEM's most valuable feature is the simplicity in handling multi-tenancy and the ability to switch between different clients at the same time. That was handled flawlessly.
What needs improvement?
The interface needs some improvements because it's a bit cumbersome when you're trying to view items. It takes some time to get used to. Additionally, sometimes the scrolling does not work.
For how long have I used the solution?
I have been using Fortinet FortiSIEM for one year.
What do I think about the stability of the solution?
Fortinet FortiSIEM is stable.
What do I think about the scalability of the solution?
The scalability of Fortinet FortiSIEM is good.
How are customer service and support?
We have contacted the support a number of times and they were helpful.
How was the initial setup?
The initial setup of Fortinet FortiSIEM is straightforward. It took us approximately two weeks.
What about the implementation team?
We did the deployment in-house. We had two people for the implementation.
What was our ROI?
We are using Fortinet FortiSIEM to serve clients, and we are receiving our return on investment from them.
What's my experience with pricing, setup cost, and licensing?
The price of Fortinet FortiSIEM was reasonable compared to other solutions.
There are many licenses required, such as the MSSP, Agent, and device. For the number of devices that you are monitoring, you need licenses. The license you pay per your usage. When you are onboarding more clients onto it, the license fee is for the usage. Additionally, there's the Windows Agent license that you need. If you use any Windows Agent, you receive a separate license charge.
What other advice do I have?
We started using Fortinet FortiSIEM because we were recommended to use it by a trusted source.
My advice to others would be to carefully look at the cost involved, and look closely at the licensing model. If it's a model that works for you, then great. However, it came as a surprise to us, we were told that we would be giving different licenses for the devices, and for the Windows Agent separately. We were not expecting the additional costs, it caught us off guard.
I rate Fortinet FortiSIEM a six out of ten.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Fortinet FortiSIEM
November 2024
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
814,649 professionals have used our research since 2012.
Network Security Engineer at Go Faster
Easy to set up and use, with quick and helpful technical support
Pros and Cons
- "It's very easy for anyone to work with."
- "We need to see incident reports about the event log, without events from the administrator or through human interaction."
What is our primary use case?
We use FortiSIEM to protect our customers.
Our current client has 20 branches and we can connect from any branch to their headquarters. We have high availability between headquarters and branches via the VPN connection. We can protect our SD-WAN, as well.
How has it helped my organization?
Fortinet is very helpful for our customers.
What is most valuable?
Every feature is good. This is one of the greatest SIEM products on the market. The most valuable feature this solution offers is that it protects the server and the client.
It's very easy for anyone to work with. You don't need any help externally.
What needs improvement?
This is a great product for everyone. The disadvantage is the product portfolio.
We need more incidents automatically to protect our network.
We need to see incident reports about the event log, without events from the administrator or through human interaction.
In the next release, I would like to have automated generation reports of incident reports.
For how long have I used the solution?
I have been using this solution for three years.
What do I think about the stability of the solution?
This solution is stable.
What do I think about the scalability of the solution?
It's a scalable product.
Fortinet has a large number of products with many modules.
We can use it for small, medium, and large enterprise companies. This product is suitable for all business sizes.
How are customer service and technical support?
Support is very helpful. They have support in our local area and there are five or six support branches worldwide.
We can contact them through Facebook, the website, on chat, and using the phone with no problem.
They are helpful and they respond quickly.
Which solution did I use previously and why did I switch?
We only use Fortinet products.
I work with version 5, version 6, and version 6.2.
How was the initial setup?
The initial setup is very easy. It's straightforward.
One person can do the basic installation and maintenance. One person can support engineers.
Every product that Fortinet offers is easy to install and can easily be deployed by one person.
You can deploy and execute one device in one day. If the project is large then you will need two or three days to complete the installation. This includes time for troubleshooting if needed.
What's my experience with pricing, setup cost, and licensing?
Pricing is acceptable for more than 90% of our customers, as they normally get discounts.
What other advice do I have?
My advice would be to know this solution, and study it well to avoid mistakes.
The configuration is simple, not complex. It's a very good product. I have not experienced any issues with it.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Security Technical Manager at a tech services company with 51-200 employees
Offers good integration capabilities with multiple tools from different vendors
Pros and Cons
- "Fortinet FortiSIEM needs to provide better API integrations to users."
- "Fortinet FortiSIEM needs to provide better API integrations to users."
What is our primary use case?
I implemented Fortinet FortiSIEM in my company to collect all logs from old systems, networks, and security devices in the network. Fortinet FortiSIEM has a correlation rule, and from it, you can generate incidents and get analytics. The tool also serves as a threat intelligence and integration platform. With FortiGuard or any third-party tools, Fortinet FortiSIEM, as a threat intelligence platform, can enrich the log attributes or criteria, which is well reflected in incidents.
What is most valuable?
The most valuable feature of the solution for the detection of threats stems from FortiSIEM's components, including the threat intelligence platform and the ability to provide integrations.
What needs improvement?
Fortinet FortiSIEM is a better solution than other products. As a SIEM solution, it can meet all the requirements of customers.
The product already offers good integration capabilities with multiple vendors. There will be new products being introduced every day in the market, so Fortinet FortiSIEM needs to ensure integrations are possible with the new tools. Fortinet FortiSIEM needs to provide better API integrations to users. Better support services can help you deal with the integration party easily. API integration capabilities will make it easy to integrate Fortinet FortiSIEM with new products unless such tools have custom or special configurations set by the vendor or the device.
For how long have I used the solution?
I have been using Fortinet FortiSIEM since 2018.
What do I think about the stability of the solution?
Stability-wise, I rate the solution a nine out of ten.
If every device can get a ten out of ten in terms of stability, then I believe it is a 100 percent perfect product.
What do I think about the scalability of the solution?
It is an easily scalable solution. Suppose you want to increase the scalability in seconds. You can increase the number of tools with an HA supervisor to handle multiple events per second, and you can use multiple collectors for remote defense. It is easy to manage the tool's scalability and availability.
My company deals with around six customers who use the product.
How are customer service and support?
The solution's technical support is good. If you want to deal with the issues from the tool of other vendors, Fortinet's support team provides help.
How was the initial setup?
The product's initial setup phase is easy.
In Fortinet FortiSIEM, with multiple tenants, one does not need to invest in the implementation process.
After the virtual machine deployment or hardware appliance initial configuration, I think network discovery is the first step in the installation process. The process continues with vendor discovery and asset inventory at customer sites. Three intelligence integrations are the second step, and the configuration with the customer's devices to send all logs to SNMP TRAPS and then to the SIEM solution is a part of the main basic implementation. If you have some configurations and event handler and event order and logs, the initial configuration can be managed depending on the needs of customers.
What's my experience with pricing, setup cost, and licensing?
I don't have the price list of any of the competitors of Fortinet FortiSIEM. I work with the technical part of the tool.
There is a need to make yearly payments towards the licensing charges attached to the product. The free version license of the product is available for two months.
What other advice do I have?
The product offers multiple integrations with all vendors. If there is a new or unknown vendor in the market, a custom API can be made to ensure that integration with Fortinet FortiSIEM is possible.
I rate the integration capabilities of the tool a nine out of ten.
The implementation of the product can improve incident response time according to the arrangement and local relation of built-in rules or custom rules. This will reduce the time of incident response, especially if you use a SOAR solution with it. You can enrich the tool by buying a SOAR solution.
It is a good product in general. It is a product that offers stability and scalability with a multiple and wide range of built-in rules. The solution is also easy to use.
I rate the tool a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
Last updated: May 3, 2024
Flag as inappropriatePrincipal Solution Architect- Security & Privacy at Sify Technologies
Less costly than other products, but needs more marketing
Pros and Cons
- "Fortinet FortiSIEM is less costly than other products and is available 24/7."
- "Fortinet FortiSIEM is a little out of sight and needs more marketing efforts to be popular in the market."
What is our primary use case?
We have an MSSP license and provide services to customers from various verticals like manufacturing, pharmaceutical, and MRD (Manufacturing, Retail & Distribution). We provide the services of Fortinet FortiSIEM to customers who cannot avail of costly on-premise services.
What is most valuable?
Fortinet FortiSIEM is less costly than other products and is available 24/7.
What needs improvement?
Fortinet FortiSIEM is a little out of sight and needs more marketing efforts to be popular in the market.
For how long have I used the solution?
We have been using Fortinet FortiSIEM for almost one and a half years.
What do I think about the stability of the solution?
The stability of Fortinet FortiSIEM is good.
What do I think about the scalability of the solution?
Fortinet FortiSIEM has good scalability.
How are customer service and support?
I have faced no issues with Fortinet FortiSIEM’s customer support.
How was the initial setup?
The deployment of Fortinet FortiSIEM, which included the migration of 30 plus customers and the initial setup of all components, did not take more than a month.
What's my experience with pricing, setup cost, and licensing?
Fortinet FortiSIEM is cheaper compared to other products.
What other advice do I have?
I use the latest version of Fortinet FortiSIEM. We have deployed Fortinet FortiSIEM on VMware.
Overall, I rate Fortinet FortiSIEM a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer:
Cyber Security Analyst at a retailer with 1,001-5,000 employees
Has easy access to create rules, playbooks, or use cases
Pros and Cons
- "I like the various options, including the option for CMDB and the easier access to create rules, playbooks, or use cases. It's also easier to use for creating dashboards and reports."
- "With FortiSIEM, the issue has to do with the ways we can generate a report. It's not as flexible compared to that with other SIEM tools, like Splunk."
What is our primary use case?
We use it as our main SIEM tool for creating rules, creating alerts, monitoring, and accessing CMDB. We also use it to monitor a few more things related to writing security.
What is most valuable?
I like the various options, including the option for CMDB and the easier access to create rules, playbooks, or use cases. It's also easier to use for creating dashboards and reports.
What needs improvement?
With FortiSIEM, the issue has to do with the ways we can generate a report. It's not as flexible compared to that with other SIEM tools, like Splunk.
When you work with a service provider who is using FortiSIEM as a service for other clients, you cannot run more than 30 clients on one tool. You cannot onboard, which would consume more resources and would make it slower. Also, resource consumption would be high.
For how long have I used the solution?
I've been using it for a year and a half.
What do I think about the stability of the solution?
It's pretty stable. We haven't faced any critical issues with stability.
How are customer service and technical support?
We had some issues when there were a few more updates or patches, but the technical support from FortiSIEM was pretty good and got it all sorted.
What other advice do I have?
If you're using it for multi-tenant solutions, it will be pretty good, but it won't support running more than 20 clients on the same platform. It would need more resources. Even if you are implementing it for multi-tenant solutions, you would need implement fewer clients on it so that it has to use less effort.
On a scale from one to ten, I would rate it at eight.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Infrastructure Operations Manager at a computer software company with 501-1,000 employees
It provides me with operational oversight on our environment using configured dashboards and reports.
Pros and Cons
- "There are things like dashboards and reports (pre-configured and custom) that let me know that things are operating the way they should be, and when they are not."
- "The biggest thing that could be better is a quicker response to support cases."
Improvements to My Organization
In large-sized medium-sized and a small-sized organizations, it improves the ability to quickly drill down into events that occur, perform analysis, and find root cause. The most value I’ve found in it, quicker time-to-resolution.
Valuable Features
I’ve used Accelops in multiple different capacities and at several organizations. As far as my current role, I am an operations manager, and it gives me operational oversight. There are things like dashboards and reports (pre-configured and custom) that let me know that things are operating the way they should be, and when they are not. Reports and Alerts help identify security risks, identify performance problems, and help in capacity planning.
Room for Improvement
The biggest thing that could be better is a quicker response to support cases.
Stability Issues
As I keep the system updated it helps to keep the system stable, but it’s been extremely stable and extremely reliable.
Scalability Issues
I have scaled it out with multiple workers and collectors. It’s scaled in every direction that I would like it to, geographically and from a correlation and reporting capacity standpoint.
Customer Service and Technical Support
I’ve had lots of different engagements with support over the years and generally I’ve had very good support, knowledgeable staff and occasionally you’ll have a weird problem, longer to resolve than some other problems; but generally speaking, the support’s been very good.
I’ve used the product for a long time so I’ve requested quite a few different features. Those features have always been added, and it’s been more or less the time they need depending on what the feature is.
Initial Setup
It’s not harder than any other similar product. It’s very easy to set up in the fact that they provide an OVA file that you can quickly and simply download and with a few configuration settings be on the network. There are multiple other deployment options for other hypervisors as well as bare metal deployments. More than anything the troubles come with configuring all of your log sources to send the necessary log messages. That’s true for any product, not just Accelops.
Other Advice
My advice would be to come up with a game plan to figure out exactly what devices or what system to focus on. Then (once you become familiar with reporting, alerting and tuning) integrate more devices/systems into Accelops.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Solutions Architect at In2IT Technologies
Useful behavior data monitoring, helpful support, and different deployment methods available
Pros and Cons
- "The most valuable feature of Fortinet FortiSIEM is the user and entity behave as analytics(UEBA). This feature mixes your data and provides useful information based on the behavior of the targeted."
- "The UI could improve in Fortinet FortiSIEM. Humans view the UI frequently for data and if it was more visually pleasing it would be beneficial."
What is our primary use case?
Fortinet FortiSIEM is used to retrieve logs from different sources, such as network switches, firewalls, and servers, that are running difficult operating systems. The solution adds intelligence to the process that can provide meaningful information for the data analyst to use.
The solution can be deployed on the cloud or on-premise.
What is most valuable?
The most valuable feature of Fortinet FortiSIEM is the user and entity behave as analytics(UEBA). This feature mixes your data and provides useful information based on the behavior of the targeted.
What needs improvement?
The UI could improve in Fortinet FortiSIEM. Humans view the UI frequently for data and if it was more visually pleasing it would be beneficial.
For how long have I used the solution?
I have been using Fortinet FortiSIEM for a couple of years.
What do I think about the stability of the solution?
The stability of Fortinet FortiSIEM is stable.
I rate stability Fortinet FortiSIEM an eight out of ten.
What do I think about the scalability of the solution?
Fortinet FortiSIEM is known for its scalability, it scales well.
We have a couple of customers using this solution.
I rate the scalability of Fortinet FortiSIEM a nine out of ten.
How are customer service and support?
The support from Fortinet FortiSIEM is great.
How was the initial setup?
The initial setup is easy, but the time it takes for the deployment depends on the number of applications monitored. One of our clients has taken us three weeks, but a typical setup takes one month. Some logs are simple to configure while others can be more difficult.
Deploying the solution is a straightforward process that involves just a few steps, such as loading the solution and configuring it, after which the solution will commence retrieving the data.
What about the implementation team?
We do the implementation of the solution with two administrators within one month.
What's my experience with pricing, setup cost, and licensing?
The price of the solution is expensive. The license is scalable. If there are 10 devices it is simple to license.
What other advice do I have?
My advice to others that might want to implement this solution is to know their business needs. There are other solutions, such as Splunk that can provide a lot more information when collecting data but it might not be needed for their use case. A small business would not need all the extra features of Splunk.
I rate Fortinet FortiSIEM an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: November 2024
Product Categories
Security Information and Event Management (SIEM)Popular Comparisons
Splunk Enterprise Security
Microsoft Sentinel
Microsoft Defender XDR
IBM Security QRadar
Elastic Security
SolarWinds NPM
PRTG Network Monitor
AWS Security Hub
LogRhythm SIEM
Cisco Secure Network Analytics
ThousandEyes
Nagios XI
Sumo Logic Security
Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- What Questions Should I Ask Before Buying SIEM?
- RSA-EMC vs. other SIEM products?
- What are the pros and cons of internal SOC vs SOC-as-a-Service?
- Between AlienVault and LogRhythm, which solution is suitable for Banks in Gulf Region