In large-sized medium-sized and a small-sized organizations, it improves the ability to quickly drill down into events that occur, perform analysis, and find root cause. The most value I’ve found in it, quicker time-to-resolution.
Infrastructure Operations Manager at a computer software company with 501-1,000 employees
It provides me with operational oversight on our environment using configured dashboards and reports.
Pros and Cons
- "There are things like dashboards and reports (pre-configured and custom) that let me know that things are operating the way they should be, and when they are not."
- "The biggest thing that could be better is a quicker response to support cases."
How has it helped my organization?
What is most valuable?
I’ve used Accelops in multiple different capacities and at several organizations. As far as my current role, I am an operations manager, and it gives me operational oversight. There are things like dashboards and reports (pre-configured and custom) that let me know that things are operating the way they should be, and when they are not. Reports and Alerts help identify security risks, identify performance problems, and help in capacity planning.
What needs improvement?
The biggest thing that could be better is a quicker response to support cases.
What do I think about the stability of the solution?
As I keep the system updated it helps to keep the system stable, but it’s been extremely stable and extremely reliable.
Buyer's Guide
Fortinet FortiSIEM
February 2025

Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
What do I think about the scalability of the solution?
I have scaled it out with multiple workers and collectors. It’s scaled in every direction that I would like it to, geographically and from a correlation and reporting capacity standpoint.
How are customer service and support?
I’ve had lots of different engagements with support over the years and generally I’ve had very good support, knowledgeable staff and occasionally you’ll have a weird problem, longer to resolve than some other problems; but generally speaking, the support’s been very good.
I’ve used the product for a long time so I’ve requested quite a few different features. Those features have always been added, and it’s been more or less the time they need depending on what the feature is.
How was the initial setup?
It’s not harder than any other similar product. It’s very easy to set up in the fact that they provide an OVA file that you can quickly and simply download and with a few configuration settings be on the network. There are multiple other deployment options for other hypervisors as well as bare metal deployments. More than anything the troubles come with configuring all of your log sources to send the necessary log messages. That’s true for any product, not just Accelops.
What other advice do I have?
My advice would be to come up with a game plan to figure out exactly what devices or what system to focus on. Then (once you become familiar with reporting, alerting and tuning) integrate more devices/systems into Accelops.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.

IT Security & CyberSecurity Consultant at digitalDefense Information Systems GmbH
A scalable solution with extensive customization options
Pros and Cons
- "This solution offers extensive customization options, making it possible to adapt it precisely to their requirements."
- "Customer support service could be better."
What is our primary use case?
If a customer is looking to establish a centralized monitoring and security solution, Fortinet FortiSIEM can be tailored to meet their specific needs effectively. This solution offers extensive customization options, making it possible to adapt it precisely to their requirements.
What is most valuable?
It works exceptionally well when combined with a vulnerability management solution.
What needs improvement?
Customer support service could be better.
What do I think about the stability of the solution?
It provides great stability features.
What do I think about the scalability of the solution?
Scalability is excellent, especially for our enterprise-level clients.
How are customer service and support?
I have moderate satisfaction with customer support, and we've learned to manage it adequately. I would rate it three out of ten.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
I previously worked with LogPoint, which had rigid pricing structures. In contrast, we value flexibility and aim to provide more adaptable support, so we switched to Fortinet FortiSIEM.
How was the initial setup?
The initial setup is quite swift.
What about the implementation team?
The deployment process usually takes just one to two days to have the basics up and running. This involves connecting the collectors and configuring the systems.
What's my experience with pricing, setup cost, and licensing?
Pricing is determined based on the customer's budget. We discuss how to tailor the pricing to fit the specific needs and financial considerations of the customer.
What other advice do I have?
I would highly recommend it. It's a top-tier solution, receiving a solid ten out of ten rating.
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Buyer's Guide
Fortinet FortiSIEM
February 2025

Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
Solutions Architect at In2IT Technologies
Useful behavior data monitoring, helpful support, and different deployment methods available
Pros and Cons
- "The most valuable feature of Fortinet FortiSIEM is the user and entity behave as analytics(UEBA). This feature mixes your data and provides useful information based on the behavior of the targeted."
- "The UI could improve in Fortinet FortiSIEM. Humans view the UI frequently for data and if it was more visually pleasing it would be beneficial."
What is our primary use case?
Fortinet FortiSIEM is used to retrieve logs from different sources, such as network switches, firewalls, and servers, that are running difficult operating systems. The solution adds intelligence to the process that can provide meaningful information for the data analyst to use.
The solution can be deployed on the cloud or on-premise.
What is most valuable?
The most valuable feature of Fortinet FortiSIEM is the user and entity behave as analytics(UEBA). This feature mixes your data and provides useful information based on the behavior of the targeted.
What needs improvement?
The UI could improve in Fortinet FortiSIEM. Humans view the UI frequently for data and if it was more visually pleasing it would be beneficial.
For how long have I used the solution?
I have been using Fortinet FortiSIEM for a couple of years.
What do I think about the stability of the solution?
The stability of Fortinet FortiSIEM is stable.
I rate stability Fortinet FortiSIEM an eight out of ten.
What do I think about the scalability of the solution?
Fortinet FortiSIEM is known for its scalability, it scales well.
We have a couple of customers using this solution.
I rate the scalability of Fortinet FortiSIEM a nine out of ten.
How are customer service and support?
The support from Fortinet FortiSIEM is great.
How was the initial setup?
The initial setup is easy, but the time it takes for the deployment depends on the number of applications monitored. One of our clients has taken us three weeks, but a typical setup takes one month. Some logs are simple to configure while others can be more difficult.
Deploying the solution is a straightforward process that involves just a few steps, such as loading the solution and configuring it, after which the solution will commence retrieving the data.
What about the implementation team?
We do the implementation of the solution with two administrators within one month.
What's my experience with pricing, setup cost, and licensing?
The price of the solution is expensive. The license is scalable. If there are 10 devices it is simple to license.
What other advice do I have?
My advice to others that might want to implement this solution is to know their business needs. There are other solutions, such as Splunk that can provide a lot more information when collecting data but it might not be needed for their use case. A small business would not need all the extra features of Splunk.
I rate Fortinet FortiSIEM an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Solution Architect at Tiger IT Bangladesh Limited
The solution's ability to collect data from different sources is its most valuable feature
Pros and Cons
- "It works well with medium to large-scale enterprises."
- "They should enhance the solution's AI capabilities, including XDR and EDR."
What is most valuable?
The solution's ability to collect data from different sources is its most valuable feature.
What needs improvement?
They should enhance the solution's AI capabilities, including XDR and EDR.
For how long have I used the solution?
We have been using the solution for six months.
What do I think about the stability of the solution?
I rate the solution's stability as a nine.
What do I think about the scalability of the solution?
I rate the solution's scalability as an eight. It works well with medium to large-scale enterprises.
How are customer service and support?
The solution's tech support team is good.
How was the initial setup?
The solution's initial setup is a bit complex as you have to do a lot of configuration. You have to collect data from different sources such as Microsoft, IBM, etc. The data extraction process differs for every system. Thus, you have to apply different protocols to collect data from various sources.
What other advice do I have?
The solution has a lot of network solutions in its bucket. As a result, they provide excellent network strength. I advise others to know the product well before implementing it. I rate it as an eight.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Research Associate at a comms service provider with 1,001-5,000 employees
Good solution for security detection and response
Pros and Cons
- "Our customer did not have security monitoring in the first place. With this solution, it provided security posture management and visibility about the security landscape and threats that they had."
- "The product does not have Security Orchestration and Automation Response, I would recommend adding this feature."
What is our primary use case?
My company is a partner of Fortinet FortiSIEM. We are a service provider and I take the solution from Fortinet and deploy it for my customers. We use the solution for security detection and response. This is a customer based solution, our customer's security admins and security operations use the solution, compromised of a team between three to five people.
How has it helped my organization?
Our customer did not have security monitoring in the first place. With this solution, it provided security posture management and visibility about the security landscape and threats that they had.
What is most valuable?
Fortinet FortiSIEM combines the SOC and NOC into a single solution with a single pane of glass. This feature on its own is next level and its easy to handle.
What needs improvement?
Fortinet FortiSIEM should consider converting the purchase model from a CapEX investment into a pay-per-use model. By doing this, it will be more attractive for more customers.
The product does not have Security Orchestration and Automation Response, I would recommend adding this feature.
For how long have I used the solution?
I have been using Fortinet FortiSIEM for two years.
What do I think about the stability of the solution?
Stability is very good.
What do I think about the scalability of the solution?
Fortinet FortiSIEM is scalable.
How are customer service and support?
Technical support is perfect.
How was the initial setup?
The initial setup of Fortinet FortiSIEM was easy. The deployment took a week and a half and was based on a project plan. You don't need more than two people to deploy and maintain this solution.
What about the implementation team?
We use an integrator for the deployment of Fortinet FortiSIEM.
What's my experience with pricing, setup cost, and licensing?
The price of Fortinet FortiSIEM is manageable. The cost is approximately $90,000 on an annual basis.
What other advice do I have?
Before fitting the product into your environment, make sure you have the right requirements.
I would rate Fortinet FortiSIEM a 9 out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Network Security Engineer at Spectrotel
Correlates incidents between products and notifies our SOC accordingly
Pros and Cons
- "It gives us the opportunity to generate notifications based upon rules that get triggered, and the rules could be specific to PCI, HIPAA, GIBA, NIST, and so forth."
- "The backup and recovery process for this solution needs improvement."
What is our primary use case?
We are a partner, and we use this solution to ingest our customers' syslogs data for their firewalls.
How has it helped my organization?
This solution allows us to ingest syslogs from Fortinet firewalls and other products into what we call FortiSIEM. This is a processor that correlates it with the event types and incidents. It gives us the opportunity to generate notifications based upon rules that get triggered, and the rules could be specific to PCI, HIPAA, GIBA, NIST, and so forth. All of these incidents are now correlated and sent up to a dashboard or emailed, where, as a SOC, we can review these incidents and triage the necessary resolution.
What needs improvement?
The backup and recovery process for this solution needs improvement.
I would like to see a database with more structure in terms of maintenance and ease of use. The process of creating is much simpler than that of duplication. The procedures are not proper for handling its PostgreSQL database.
For how long have I used the solution?
More than two years.
What do I think about the stability of the solution?
I would say that this solution is stable when it is configured and deployed by the Fortinet professional team.
What do I think about the scalability of the solution?
The scalability is there, and you can expand on the EPS (Events Per Second) as needed.
We do plan on selling this service to our customers that can see the benefit in it. We will probably introduce an incident response application to help triage incidents at a faster level.
How are customer service and technical support?
Technical support is very good. The people in support are excellent, and they know this product in and out. They are very quick to respond and the resolution is very quick.
How was the initial setup?
The initial setup for this solution is straightforward, although we are not yet in full production. During the past two years, while we have been implementing, we have found a lot of bugs in the software. As such, we're still not in a state where we can go into full production. For example, if you are certified for PCI then one of the standards is that you have to have proper backup recovery in place. This solution is lapsing in that area.
Two staff are required for deployment and maintenance.
What about the implementation team?
We used Fortinet consultants for the deployment.
What's my experience with pricing, setup cost, and licensing?
We bought the perpetual license, so we own the product, but there is a three-year support renewal fee for that.
Which other solutions did I evaluate?
We did evaluate Splunk before choosing this solution, but it was too much on the high end for our business model.
What other advice do I have?
We are very impressed with this product. However, they have to fix their backup and recovery procedure and provide a good DR service without charging for a secondary license.
I would rate this solution a seven and a half out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
Information Security Officer at a aerospace/defense firm with 10,001+ employees
We like its visibility and flexibility. It allows us to get real-time, accurate, situational awareness of what's going on.
Pros and Cons
- "We're able to get real-timec as well as our customer networks that we're monitoring at all times."
- "The dashboards need to be improved. It gives you so much detail, but sometimes too much detail, especially to an executive, it's too much."
How has it helped my organization?
We're able to get real-timec as well as our customer networks that we're monitoring at all times.
What is most valuable?
- Visibility
- Flexibility
What needs improvement?
The dashboards need to be improved. It gives you so much detail, but sometimes too much detail, especially to an executive, it's too much. I need to be able to understand what my situational awareness is by looking at a simple graph. I've already made a specific feature request to just make it look sexier because that's what customers like to see.
What do I think about the stability of the solution?
The stability has been very good. We've had no issues with instability.
What do I think about the scalability of the solution?
What we really like about it is the ability to scale without costing an arm and a leg for us. They're highly virtualized and, as a result, we're able to deploy in a lot faster manner than shipping their metal to a location that might have to be purchased in another state or country.
How are customer service and technical support?
We have used their technical support as well as their customer service. They've always got back to us in a timely manner. We've never had an issue of being able to get to the right person. If it doesn't get to the right person, it gets escalated very fast.
Which solution did I use previously and why did I switch?
We used LogRhythm, and Accelops replaced it.
How was the initial setup?
I wasn't involved in the initial setup, but my team was.
What other advice do I have?
You always have to do your due diligence. I'm pretty sure a lot of the other competition is just as capable, however we deal with aircrafts, which is a different, unique beast. It enables us to understand an aircraft or sat-com network infrastructure, so it's not like a traditional type of log file that you have to normalize.
Some companies work with Windows desktops and servers, but we don't. Again, be sure to do your due diligence because whether Accelops is right for you depends on your use case. Make sure also that you have an MSSP model like we do so that you're able to deliver for your customers.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Manager, Security Services at a financial services firm with 5,001-10,000 employees
We like the built-in reports and alerts, along with the extreme flexibility in reporting and rule generation.
Pros and Cons
- "The most valuable features for us are the built-in reports and alerts, along with the extreme flexibility in reporting and rule generation."
- "Creating parsers to try make unknown events or currently unsupported devices produce meaningful information is extremely cumbersome."
How has it helped my organization?
There are several examples, but the flexibility in reporting and alerting has given us the ability to have numerous teams be alerted for various security situations affecting each team's responsibilities.
What is most valuable?
The most valuable features for us are the built-in reports and alerts, along with the extreme flexibility in reporting and rule generation. The logs and search engine are also valuable features.
What needs improvement?
Creating parsers to try make unknown events or currently unsupported devices produce meaningful information is extremely cumbersome.
Additionally, lately there have been releases which have broken existing functions. This directly relates to support being an area that also needs improvement.
What do I think about the stability of the solution?
In general, the system is stable.
What do I think about the scalability of the solution?
We had to deploy several workers to keep up with event collection. This was one reason that the AO agent was developed and released -- to reduce the load on the managers and workers.
How are customer service and technical support?
Customer Service:
Customer service is mediocre, but the relationship is improving with focused attention on customers.
Technical Support:
Technical support is good.
Which solution did I use previously and why did I switch?
We were a a Cisco MARS customer and needed to replace the solution once Cisco ceased support.
How was the initial setup?
The initial setup is straightforward. There is a learning curve for the software, but overall it was up and running and collecting information in a matter of an hour post setup.
What about the implementation team?
We implemented it with out in-house team.
Which other solutions did I evaluate?
We didn't evaluate other options as this was a direct, suggested replacement to MARS.
What other advice do I have?
Watch the sizing requirements for the virtual machines and quantities needed to support the environment. Make sure you get sign-off from Accelops on proposed the configuration and load for what’s being planned on the deployment.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.

Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2025
Product Categories
Security Information and Event Management (SIEM)Popular Comparisons
Microsoft Sentinel
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Rapid7 InsightIDR
Sumo Logic Security
AlienVault OSSIM
Securonix Next-Gen SIEM
Google Chronicle Suite
ManageEngine Log360
USM Anywhere
Sentinel
Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?
- What Questions Should I Ask Before Buying SIEM?
- What are the pros and cons of internal SOC vs SOC-as-a-Service?