What is our primary use case?
I work in our presales department. We have three of our clients using Fortinet FortiSIEM.
The solution is useful to integrate logs from different sources so that there is a common place to see and create dashboards and the AI associated with event checking.
We have a common service desk for our customers that has three employees monitoring everything. It requires less than one person to watch the dashboards, send the alerts and call the back office during an event. The solution requires maintenance every three months to install the last stable version of the firmware.
How has it helped my organization?
FortiSIEM helped us discover all the threats at the time that were attacking the IT services of the company. We now have multiple-level authentication. We use VPN instead of publishing services to the world, and we closed some services that are no longer being used. Eventually, we geographically blocked some services that do not need to be published in China or the United States, for example.
What is most valuable?
FortiSIEM has been a good product. It does everything that it has promised that it can do. It has been very useful to discover new threats from the outside such as external exploits, brute-force, or password tries.
What needs improvement?
The process of installing Fortinet FortiSIEM and the customization of the alerts take too long. You need to customize the alerts that come to the dashboard so that not everything is an alert. If everything is an alert, nothing is an alert. This is a complicated process and takes time.
In future releases, I would like to see a resource for common environments like VMware and VMware/FortiGate or VMware/Check Point. The resource should discover and speed up implementation.
Buyer's Guide
Fortinet FortiSIEM
November 2024
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
814,649 professionals have used our research since 2012.
For how long have I used the solution?
We have been using Fortinet FortiSIEM for a year and a half.
What do I think about the stability of the solution?
Being a Linux virtual appliance, FortiSIEM is a stable platform.
What do I think about the scalability of the solution?
We are located in Uruguay, which is a small country. We have no issues with scalability because we have so few people and our IT infrastructure is quite simple.
Our customers have between 200 and 400 users of Fortinet FortiSIEM.
How are customer service and support?
I would rate the customer service and support of Fortinet FortiSIEM a four out of five. They are quite good.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Prior to FortiSIEM, we did not use SIEM. We had a log concentrator, but it did not have the ability or the AI to correlate logs like SIEM has.
We decided to implement FortiSIEM because SIEM has the ability to create logs using AI. With a log concentrator, we have all the events there, but there is no relation between them and what we have to do manually.
How was the initial setup?
The initial setup of Fortinet FortiSIEM is easy. The solution is on a virtual appliance that you download and put in the VMworld or on-premise. I would rate the ease of initial setup a five out of five.
What about the implementation team?
Deployment and implementation of FortiSIEM took three months due to the tuning and the building of the dashboards. We used Fortinet professional services for our first deployment. For the second deployment, we used our in-house team.
What was our ROI?
We are seeing very good results on a security level.
What's my experience with pricing, setup cost, and licensing?
Fortinet's products are not expensive, it is less than the competition. There are additional fees for space in the virtual environment. You require virtual space because the logs take up space on the disk. Eventually, you need to buy disks and put them in your environment or in the cloud. Without the disk, you have to turn off the device.
I would rate them a three out of five overall for pricing.
Which other solutions did I evaluate?
We did consider Sentinel in Azure because it is almost free.
What other advice do I have?
If you are considering Fortinet FortiSIEM for your organization, write down what alerts are important to you, which devices deserve to be monitored, and which logs you really need. You will need to customize all of this. If you have all of this detailed, the implementation process will be easier.
I would rate the solution an eight out of ten overall.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Presently on 4.10 version. You must deploy using Workers and Collectors. Or else the Supervisor take control of all the memory, Currently the Country location and IP does not match up. report as a Bug since v 4,2 version