The event correlation is pretty robust. The GUI is pretty good.
Fortinet FortiSIEM offers flexible reporting and rule generation with built-in reports and alerts, integrating SOC and NOC operations for robust monitoring. Seamless integration with platforms like Cisco and Palo Alto enhances interoperability. It provides strong event correlation for threat detection, but creating parsers for unsupported devices is cumbersome. Documentation needs improvement, especially on CLI features, and integration can be challenging. Technical support is often criticized, and the licensing model is seen as expensive.