We primarily use the solution for network and security monitoring.
Partner at a security firm with 11-50 employees
Good network monitoring with excellent scalability and good stability
Pros and Cons
- "The stability is very reliable. It offers very good performance."
- "The policy editing should be easier. Right now, it's too hard."
What is our primary use case?
What is most valuable?
Most of those CM functions and the correlation alerts are very helpful to our clients.
The network monitoring is one of the most valuable aspects of the solution.
You can scale the solution with ease if you need to expand.
The stability is very reliable. It offers very good performance.
What needs improvement?
The initial setup is complex. They need to make it easier in terms of implementation. That said, all CM implementations are quite difficult. It may not be a fault of this particular product.
The policy editing should be easier. Right now, it's too hard.
Some of the parts of the mapping tool should be in the product itself. It would make our efforts easier.
The product is quite expensive. It's something clients always comment on.
For how long have I used the solution?
We have been using the solution for many years - including before Fortinet acquired the original organization.
Buyer's Guide
Fortinet FortiSIEM
January 2025
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,158 professionals have used our research since 2012.
What do I think about the stability of the solution?
The solution is quite stable. We find it very reliable. It doesn't crash or freeze. There aren't bugs and glitches.
What do I think about the scalability of the solution?
The scalability of the solution is excellent. It's one of the main reasons we chose to go with this option. If a company needs to expand, it can do so easily. There aren't constraints.
We have about five to ten customers on the solution currently.
How are customer service and support?
I'm not using the vendor's technical support. Mostly we have our own in-house resources. I cannot tell if are they good or bad. I have never dealt directly with them. Therefore, it would be difficult to review their services.
How was the initial setup?
In terms of the initial setup, the process is not straightforward. It's complex and difficult. Making it easier would help a lot.
All CM installations and implementations are complicated. You have to tailor the product. It's not really something you can just implement out-of-the-box.
That said, a basic installation is simple. It takes a few days. After you've done the implementation stage, then it takes time. Of course, it depends on the projects. I cannot say how much time it's taken exactly. I just know it takes quite a while.
For deployment, we use two people in a project. One of them is for the beginning of the project - for the implementation and the installation process. The other is the administration which we are generally pas off to our customers. I tend to handle the daily operations.
What's my experience with pricing, setup cost, and licensing?
All of our customers find the solution expensive. It's not a cheap option.
I don't know the exact cost of the solution as I don't directly handle the licensing.
What other advice do I have?
We are actually a reseller service company and we are dealing with the solutions for our customers. We are using the SIEM solutions. We are not a user, we are a reseller.
We have many customers. Not all may be using the latest version of the solution.
I would recommend the solution.
In general, I would rate the solution eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
IT Executive: Operations & Security at Icon Information Systems (Pty) Ltd
The performance is very good, and it is extremely scalable
Pros and Cons
- "To add workers and even collectors is pretty easy."
- "The dashboard needs to improve."
What is our primary use case?
We run a Manage Security Services company and we use it in-house and for some of our clients. The service is a multitenant platform where our clients can log on to view and access various security-related activities and features. In more ways, it becomes like a cloud solution to them. We make use of a secure connection from the clients’ networks using collectors located on their premises back to our centralized SIEM platform.
What is most valuable?
The most valuable feature is the differentiator, which has a combination of not only the SOC which covers the security operations aspect, but it also includes NOC capabilities. FortiSIEM uses PAM (Performance, Availability, and Monitoring) from an NOC perspective. So not only do you natively look at security data as most SIEM solutions, but you're also looking at the performance and the availability component of those devices. It's easy for us to coordinate if a security incident occurs. You're not only looking at security logs but you also looking at what could potentially have happened in terms of device performance. So that feature to me already makes it quite a big differentiator in the market, compared to other SIEM tools out there.
What needs improvement?
When they started out after acquiring AccelOps, the user interface wasn't that great. But from version 5.0 they have obviously radically changed the interface, aligning it to the rest of the Forti products from a user experience point of view. This means that there is constant improvement on the interface side of the solution. The other thing that I've noticed is when searching for very old incidents, there is a slight delay. It obviously has to pull that information from the backend database, and the key point to note is that it depends on how you set it up in the backend where factors such as disk types and disk array configs come into play.
For how long have I used the solution?
I have been using this solution for 18 months now.
What do I think about the stability of the solution?
The solution is quite solid and stable.
What do I think about the scalability of the solution?
The scalability component is easy. To add workers and even collectors is easy which is how we've deployed it, makes scalability much easier. We plan to grow our users into the thousands.
How are customer service and technical support?
I never really used support from Fortinet for the FortiSIEM solution that frequent because I figured most of the stuff out on my own, but that being said, the Fortinet Support is great because I figured most of the stuff out on my own.
How was the initial setup?
The initial setup was quite complex. We've had some issues with the first OVF file that we downloaded. We had to customize the installation processes. It was a bit complex in the earlier versions, but the newer versions have greatly improved.
What other advice do I have?
We use an on-premises deployment model from our perspective and a hybrid model from a customer/user perspective.
I will recommend this solution to others out there looking for a SIEM solution. I've already done a few events we were talk about FortiSIEM and its advantages. I do, however, think the main dashboard where you create and design your graphs could do with some improvement improved. On a scale from 1 to 10, I will rate this solution an 8 to ensure there’s continuous improvement.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Fortinet FortiSIEM
January 2025
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,158 professionals have used our research since 2012.
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
The product is a well rounded performer when it comes to combined Infrastructure and Security monitoring, however in traditional SIEM bake-offs, they need a lot more flavour to make it exciting.
Introduction:
How many of you remember Cisco MARS? Well, if you don’t, let me remind you that they were one of the earliest SIEM products around that stemmed from the infrastructure monitoring space. MARS was geared more towards monitoring and reviewing network infrastructure including their utilization, performance availability and logs. After a brief run in enterprises that were Cisco heavy, the product died a natural death. People who were involved in the product left Cisco and started AccelOps (Accelerate Operations). As a product, they took the fundamentals of data collection and integrated infrastructure log, event monitoring to the data analytics platform. The result is a promising product called AccelOps.
They have since been acquired by Fortinet, marking their foray into the larger Enterprise SIEM market dominated by the likes of HP, IBM, Splunk, etc.
AccelOps:
As you can guess, by virtue of collecting data from various sources like network devices and servers, AccelOps is a product that provides fully integrated SIEM, file integrity monitoring (FIM), configuration management database (CMDB), and availability and performance monitoring (APM) capabilities in a single platform.
- APM Capability: This is their strong suit and it is MARS on steroids. AccelOps excels in capturing statistics to provide insights into system health. This provides value in a MSSP/NOC/SOC setup as there is no need for an additional monitoring platform. Again, Syslog or SNMP are your best bets for APM.
- File Integrity Monitoring: Very few SIEM products (think AlienVault) offer native FIM capabilities and to see it in AccelOps is refreshing. The way they do so is no surprise as FIM can only be done effectively using an agent-based approach and Accelops does the same.
- CMDB: AccelOps has the capability to keep track of all the elements in an organisation’s network infrastructure like network devices, UPS, servers, storage, hyper-visors, and applications. Using the data, a Centralised Management Database (CMDB) is available in AccelOps. This again is very unique and even AlienVault with all its Unified SIEM branding, does not shine as much as AccelOps does.
- SIEM: Now that all the data from various network infrastructure is available in AccelOps along with CMDB, the ability to cross-correlate, in real-time, becomes easy and AccelOps does that using its own patented correlation engine. The SIEM capability comes with all the bells and whistles one would expect – rules, dashboards, alerting, analytics, intelligence, etc.
Now let us look at the Strengths and Weakness of AccelOps as a product
The Good:
- AccelOps’ combination of SIEM, FIM and APM capabilities in a single box helps in Centralised operations as well as security monitoring.
- AccelOps serves as a centralised data aggregation platform for system health data, network flow data, as well as event log data.
- AccelOps has a mature integration capability with traditional incident management and workflow tools like ServiceNow, ConnectWise, LanDesk and RemedyForce.
- From a deployment flexibility point of view, AccelOps excels in virtualisation environments. However, they are also available in traditional form factors. If customers prefer cloud, they are also available for deployments in either public, private or hybrid clouds.
- From an architecture perspective, they have three layered tiers.
- The Collector tier does exactly what the name suggests – collects data from end log sources.
- The Analytics tier receives data from the collector tier. This analytics tier is built on big data architecture fundamentals supporting a master/slave setup. In AccelOps terms, it is a Supervisor/Worker setup.
- The Storage tier then serves as the data sink housing the CMDB and the big data file system.
- Because of the architecture setup, the scalability is not an issue with AccelOps. It does scale well with clustering at Analytics and Storage tiers.
The Not So Good:
- The most obvious is that AccelOps as a product has relatively low visibility in the market. However, this is bound to change with the Fortinet buy. They will hopefully be seen in more competitive bids and evaluations.
- While AccelOps tries to be a “Jack of All”, it unfortunately is a master of none. This means that the product has poor support for some third-party security technologies, such as data loss prevention (DLP), application security testing, network forensics and deep packet inspection (DPI). This hinders the product's versatility in large environments.
- Parsing is a key aspect of SIEM and in this area too AccelOps lacks extensive coverage as seen amongst competition. While most of the popular ones are parsed out of the box, others require custom parser development skills, which unfortunately requires a steep learning curve or product support to help build.
- While for Network engineers and analysts the interface makes sense, from a SIEM view, the usability could definitely be improved. This issue is evident when looking at dashboards, report engines, alerts, etc., which seem to be afflicted with information overdose.
- Ease of deployment is there, however, the configuration takes a lot of time considering the fact that there are several tool integrations to be done before it can generate value. Some of the configurations are really complex and may lead to the user or admin being spooked. We were reminded of the MARS days time and again while evaluating this product.
- The UI, while presenting data in a very informative way, suffers from too much clutter, hindering usability. While this is a personal opinion, with SIEM tools comparisons against the likes of IBM, Splunk, and even LogRhythm, the AccelOps UI does not excite. We hope that Fortinet brings to the fore its UI maturity to AccelOps, thereby becoming much more savvy.
- Correlation capabilities are very good when it comes to data visibility, compliance, and infrastructure monitoring use cases. However, when it comes to threat-hunting, trend analysis, behaviour profiling, AccelOps has a lot of ground to cover.
- Without Infrastructure data, AccelOps loses its edge. As a traditional SIEM, collecting only Event logs makes it look like a pretty basic SIEM. This can be quite an issue in organisations where infrastructure monitoring is already being done by other tools. Unless customers duplicate data sets across the tools, the value is poor.
Conclusion:
All in all, the product is a well rounded performer when it comes to combined infrastructure and security monitoring, however in traditional SIEM bake-offs, they need a lot more flavour to make it exciting. Hopefully the Fortinet buy will do just that. We will continue to watch out for this product and its road map in coming months.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Enterprise Information Security Architect at a healthcare company with 1,001-5,000 employees
It provides intelligent alerting and the out-of-the-box rules don't require much tuning or management overhead.
What is most valuable?
- The automation piece -- its ability to dynamically discover which services need to be monitored and to automatically setup the appropriate monitoring.
- We also like the intelligence behind the alerting; we like the out-of-the-box rules that don’t require a lot of tuning.
- The product doesn’t require a lot of manpower, so there isn’t a lot of tuning or management overhead required for it.
How has it helped my organization?
We outsource a lot of our IT. We are able to monitor performance and security and to perofrm audits to ensure our outsourcing partners are doing what we are pay them for.
What needs improvement?
The way that upgrades are handled could be a bit cleaner. That might have been improved in the new version, but where we are, the upgrade process takes the system down for the period of the upgrade. So the lost data during that downtime can be frustrating.
For how long have I used the solution?
I've used it for four years.
What was my experience with deployment of the solution?
We did, but AccelOps were very, very helpful. I don’t think the product was configured or tuned for an environment as large as ours, so there were some performance issues at first, but they were very helpful and they had developers and engineers on the phone with us to help resolve those issues. They even used the experience with us as a test case to build improvements into the product.
What do I think about the stability of the solution?
No issues since the product was installed.
What do I think about the scalability of the solution?
No issues since the product was installed.
How are customer service and technical support?
Customer Service:
Their sales people have always been helpful and friendly, and they’ve given us some things for free, like training. It’s been good. We’ve even had some of the higher-ups at AccelOps call us with new product offerings for us because they know our organization so well.
Technical Support:I would say it’s more on the average side. Once I can get someone engaged they’re good about getting the problem solved, but sometimes it’s hard to get someone on the line to help resolve your problem.
Which solution did I use previously and why did I switch?
No, this is the first solution like this that we’ve had.
How was the initial setup?
The setup was straightforward, but the performance issues we had were the biggest stumbling block. In terms of getting it out of the box and up and running, it really wasn’t difficult at all.
What about the implementation team?
I did it myself in-house.
What's my experience with pricing, setup cost, and licensing?
The pricing is very, very affordable. For the value you get, I think it’s about the cheapest solution on the market.
What other advice do I have?
I think the biggest thing to understand is that it’s like a Swiss Army knife. You get a lot of tools for a lot of things, but don’t expect it to be a killer app in any one area.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Solutions Consultant at a comms service provider with 51-200 employees
A stable solution with good pricing, but they need to address recent changes to technical support
Pros and Cons
- "Both the collecting logs and duo correlation are valuable features for us."
- "The support of the product changed recently, and I don't think it's for the better. They should work to improve the support they offer to clients."
What is our primary use case?
We primarily use the solution for collecting logs and duo correlation on our customer's premises.
What is most valuable?
Both the collecting logs and duo correlation are valuable features for us.
Fortinet also offers very good pricing. Their pricing is incredible.
What needs improvement?
The support of the product changed recently, and I don't think it's for the better. They should work to improve the support they offer to clients.
They also have to improve their import perfection solution.
For how long have I used the solution?
I've been using the solution for 1.5 years.
What do I think about the stability of the solution?
The solution is very stable, like all Fortinet products.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and technical support?
Technical support is very good. They also provide you with additional materials to study the product by yourself so that you can get a better understanding of the full solution.
How was the initial setup?
The initial setup is complex, mostly because of the security, not because of the product. Most of the security features in the installation process are difficult. They require tuning. You have to be careful you don't configure something wrong. This is a complexity of the environment and the solution itself. The engineer should understand what the customer is looking for. The product might be very good, but if it is positioned in the wrong way, it can be harmful.
Which other solutions did I evaluate?
I did not evaluate other options; this solution was the decision of the customer. However, in the past, I have evaluated and worked with Splunk and IBM.
What other advice do I have?
We use the public cloud deployment model.
I like the product, and I would recommend it, but I much prefer Splunk.
The beautiful thing about Fortinet is that they have integrated many, many solutions. Their platform is very powerful. In the case of the customer, if he decides to choose Fortinet, he'll largely be stuck with that one vendor. Fortinet does integrate with a few other vendors, but it's best if you use only their solutions. It's more efficient, you have more manageability and you get more value that way.
I would rate the solution seven out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Manager, ICT Enterprise Services at a government with 201-500 employees
Has good business service summaries in the dashboards but it should have better integration abilities
Pros and Cons
- "Analytics is the most valuable feature. The business service summaries in the dashboards and the correlations for the SIEM are also valuable features."
- "Their product support, in general, is not that great. The product support is in the same ecosystem. Their support is improving but it's not that great.vvv"
What is our primary use case?
We use the on-prem deployment model of this solution. Our primary use case of this solution is for all of our infrastructure monitoring, applications, performance monitoring, and for security, incident, and event analysis.
What is most valuable?
Analytics is the most valuable feature. The business service summaries in the dashboards and the correlations for the SIEM are also valuable features.
What needs improvement?
Their product support, in general, is not that great. The product support is in the same ecosystem. Their support is improving but it's not that great.
It should also have better integration.
For how long have I used the solution?
I have been using FortiSIEM for four years.
What do I think about the stability of the solution?
It's a good product. It does what it is supposed to do.
What do I think about the scalability of the solution?
Scalability required a lot of training. If the training isn't adequate you cannot enjoy the end results.
There are currently around ten users using this solution. They are mostly system and network administrators using this solution. We don't have plans to increase the usage. We are going to switch to another product.
We require two staff members for the deployment and maintenance.
How are customer service and technical support?
When you log a call, you don't get instant replies or if there is a bug they take ages to fix it and they ask you to hold.
Which solution did I use previously and why did I switch?
We didn't previously use another SIEM solution.
How was the initial setup?
The installation is straightforward but the configuration is complex because it compromises of several aspects of the network infrastructure, servers, and the databases. You have to know what you want to gain out of this product.
The deployment took around three months. There are a lot of dashboards to configure. It's not about just the installation. The planning phase and understanding what you want to get out of it, setting up the logs, and working on the correlations take time.
What about the implementation team?
We used a local integrator for the deployment. They were good. When you consider the other SIEM products, this isn't a popular solution. When we implemented it, we were with the solution before it was acquired by Fortinet. It was a hassle.
What's my experience with pricing, setup cost, and licensing?
Licensing is a one time cost. If you want to enable different modules then there will be additional costs.
What other advice do I have?
Properly review this solution and your requirements. See how it will scale up to cloud requirements. Cloud technologies are becoming more prominent and you should see how you will be able to manage it with this tool.
It's a good product but you need to be well trained. If you don't have good training then you won't maximize the benefits of this product.
I would rate it a seven out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Systems Administrator with 501-1,000 employees
Dashboards provide us with the real-time status of our network, including specific alerts and granular monitoring.
Valuable Features
The granular monitoring capabilities. Also, it's very configurable.
Improvements to My Organization
It gives greater visibility via the dashboards into the real-time status of the network. Additionally, it also provides specific alerts and performance monitoring.
Room for Improvement
Some of the out-of-box dashboards could be more useful, as they’re not configured out-of-box. Some other products we’ve used give a lot more information right out of the box. With Accelops, we didn’t get quite enough useful information at the beginning. Ping monitors (STMs) are highly configurable, but it would be nice to have a simpler monitor to go with it, like a simple ping monitor. As it is, we have to go through three different processes and 30 minutes to get the ping monitor up with email notifications. It should have an easier way to configure some of these more common monitors.
Use of Solution
I've used it for two years, but the firm has had the solution in place for longer.
Stability Issues
The product is always stable, but there were a few bugs. During some of the upgrades, fixing one problem revealed another, so we had to go through several patch iterations to find a bug-free version that works for us.
Scalability Issues
None. Far more scalable than is required for us.
Customer Service and Technical Support
Customer Service:
Great - we’d give it a 10/10.
Technical Support:6/10 - as far as the techs go, they are knowledgeable, but when trying to get a hold of a tech or have them call back, they weren’t responsive. It was one of my biggest frustrations with the product, and I started to look elsewhere for another solution at one point. Issues that could have been resolved in 30-60 minutes sometimes took months, but they have improved.
Other Advice
Just do your research – the product does a lot, but it may be more than you’re looking for. Also, be aware that it requires a lot of time to maintain, set up, and configure.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Network Security Engineer at Technicom Mali
A simple setup but needs better visibility and more correlation tools
Pros and Cons
- "It is used as an alerting platform."
- "The log collection and configuration management are not great."
What is our primary use case?
It is used as an alerting platform and has an availability manager.
What is most valuable?
We already have experience with Fortinet products, so dealing with Fortinet FortiSIEM is not complicated.
What needs improvement?
They should offer better visibility, more correlation tools and a better understanding of the network. Fortinet FortiSIEM already uses simple and standard protocols like SNMP, DuraMI and Syslog. Other solutions like QRadar use sFlow, so I think that they can do better.
In addition, the log collection and configuration management are not great.
For how long have I used the solution?
We have been using this solution for three years. We deployed Fortinet FortiSIEM at about three customer sites, and it is deployed on-premises.
What do I think about the stability of the solution?
The product is stable.
What do I think about the scalability of the solution?
It is a scalable solution.
How are customer service and support?
We have expertise with the product, so we don't use technical support often. We only require support for the error mark, and the support is quick and fast for that.
How was the initial setup?
The initial setup was simple, and we deployed Fortinet FortiSIEM in two days. We already had all the information regarding the customers' notes, and it was simple, quick and fast.
What's my experience with pricing, setup cost, and licensing?
It is cheaper than LogPoint or QRadar.
What other advice do I have?
I rate this solution a five out of ten. It is not as good as other solutions like QRadar, but it's cheaper than other products and very simple. In the next release, the visibility should consist of simple and standard protocols.
Regarding advice, if you don't have a dedicated team to handle your logs, don't have a big budget, and want a solution to correlate and collect logs from many vendors, Fortinet FortiSIEM is an excellent choice.
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
Security Information and Event Management (SIEM)Popular Comparisons
Splunk Enterprise Security
Microsoft Sentinel
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Sumo Logic Security
Rapid7 InsightIDR
AlienVault OSSIM
Securonix Next-Gen SIEM
USM Anywhere
ManageEngine Log360
Google Chronicle Suite
Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?
- What Questions Should I Ask Before Buying SIEM?
- What are the pros and cons of internal SOC vs SOC-as-a-Service?
This looks like a review from another site which not a real customer review.