Try our new research platform with insights from 80,000+ expert users
Kumar Vaibhav - PeerSpot reviewer
Solutions Architect at In2IT Technologies
MSP
Apr 16, 2023
Useful behavior data monitoring, helpful support, and different deployment methods available
Pros and Cons
  • "The most valuable feature of Fortinet FortiSIEM is the user and entity behave as analytics(UEBA). This feature mixes your data and provides useful information based on the behavior of the targeted."
  • "The UI could improve in Fortinet FortiSIEM. Humans view the UI frequently for data and if it was more visually pleasing it would be beneficial."

What is our primary use case?

Fortinet FortiSIEM is used to retrieve logs from different sources, such as network switches, firewalls, and servers, that are running difficult operating systems. The solution adds intelligence to the process that can provide meaningful information for the data analyst to use.

The solution can be deployed on the cloud or on-premise.

What is most valuable?

The most valuable feature of Fortinet FortiSIEM is the user and entity behave as analytics(UEBA). This feature mixes your data and provides useful information based on the behavior of the targeted.

What needs improvement?

The UI could improve in Fortinet FortiSIEM. Humans view the UI frequently for data and if it was more visually pleasing it would be beneficial.

For how long have I used the solution?

I have been using Fortinet FortiSIEM for a couple of years. 

Buyer's Guide
Fortinet FortiSIEM
March 2026
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.

What do I think about the stability of the solution?

The stability of Fortinet FortiSIEM is stable.

I rate stability Fortinet FortiSIEM an eight out of ten.

What do I think about the scalability of the solution?

Fortinet FortiSIEM is known for its scalability, it scales well.

We have a couple of customers using this solution.

I rate the scalability of Fortinet FortiSIEM a nine out of ten.

How are customer service and support?

The support from Fortinet FortiSIEM is great.

How was the initial setup?

The initial setup is easy, but the time it takes for the deployment depends on the number of applications monitored. One of our clients has taken us three weeks, but a typical setup takes one month. Some logs are simple to configure while others can be more difficult. 

Deploying the solution is a straightforward process that involves just a few steps, such as loading the solution and configuring it, after which the solution will commence retrieving the data.

What about the implementation team?

We do the implementation of the solution with two administrators within one month.

What's my experience with pricing, setup cost, and licensing?

The price of the solution is expensive. The license is scalable. If there are 10 devices it is simple to license.

What other advice do I have?

My advice to others that might want to implement this solution is to know their business needs. There are other solutions, such as Splunk that can provide a lot more information when collecting data but it might not be needed for their use case. A small business would not need all the extra features of Splunk.

I rate Fortinet FortiSIEM an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
TamimKhan - PeerSpot reviewer
Solution Architect at Tiger IT Bangladesh Limited
Real User
Top 5Leaderboard
Mar 29, 2023
The solution's ability to collect data from different sources is its most valuable feature
Pros and Cons
  • "It works well with medium to large-scale enterprises."
  • "They should enhance the solution's AI capabilities, including XDR and EDR."

What is most valuable?

The solution's ability to collect data from different sources is its most valuable feature.

What needs improvement?

They should enhance the solution's AI capabilities, including XDR and EDR.

For how long have I used the solution?

We have been using the solution for six months.

What do I think about the stability of the solution?

I rate the solution's stability as a nine.

What do I think about the scalability of the solution?

I rate the solution's scalability as an eight. It works well with medium to large-scale enterprises.

How are customer service and support?

The solution's tech support team is good.

How was the initial setup?

The solution's initial setup is a bit complex as you have to do a lot of configuration. You have to collect data from different sources such as Microsoft, IBM, etc. The data extraction process differs for every system. Thus, you have to apply different protocols to collect data from various sources.

What other advice do I have?

The solution has a lot of network solutions in its bucket. As a result, they provide excellent network strength. I advise others to know the product well before implementing it. I rate it as an eight.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Fortinet FortiSIEM
March 2026
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.
Solution Consultant at 1&1 Versatel Deutschland GmbH
Real User
Mar 13, 2023
It's a good tool for making security processes transparent
Pros and Cons
  • "FortiSIEM is a great tool for making security processes transparent."

    What is our primary use case?

    FortiSIEM combines information from operations and integrates it into management.  

    What is most valuable?

    FortiSIEM is a great tool for making security processes transparent. 

    What do I think about the stability of the solution?

    I rate FortiSIEM 10 out of 10 for stability. 

    What do I think about the scalability of the solution?

    I rate FortiSIEM nine out of 10 for scalability.

    How was the initial setup?

    Setting up FortiSIEM is straightforward.  I prefer this product in the Fortinet environment. It's easy to install and configure.  

    What's my experience with pricing, setup cost, and licensing?

    FortiSIEM might be considered expensive in some markets. We have an international customer base, and it's affordable for a lot of them. 

    However, customers in some markets cannot build a suitable use case around it. But it's not because of the product. It often depends on customers' operation organization. 

    You also need some operation and security knowledge to make a professional management decision. 

    A company needs to work with the consultants and distributors who are delivering the environment and necessary support.

    What other advice do I have?

    I rate Fortinet FortiSIEM nine out of 10. 

    Disclosure: My company has a business relationship with this vendor other than being a customer. partner
    PeerSpot user
    reviewer1051230 - PeerSpot reviewer
    Programmer Data Center at a consultancy with 10,001+ employees
    Real User
    Top 10
    Jan 11, 2023
    Lacks a level of support we'd expect to see, particularly for patching; Threat Hunting is a great feature
    Pros and Cons
    • "The Threat Hunting feature provides complete traffic analysis."
    • "Patching is not great - we're not getting the support we'd expect."

    What is our primary use case?

    Our use case is for collecting logs and monitoring internet traffic through firewalls. We have Fortinet firewalls and Fortinet WAF. I'm a system programmer and we are customers of Fortinet. 

    What is most valuable?

    I like the Threat Hunting feature which provides complete traffic analysis, like file movement and processes. It's a good feature. 

    What needs improvement?

    We have recently faced many issues in terms of support and their turnaround time for giving support as well as their patch level. The patching is one of the significant issues we face with Fortinet SIEM. We're at the enterprise level and we're not getting the support we'd expect. They really need to bring in new features like proper dashboards and alert systems and a real-time alert system which would be beneficial for users.

    For how long have I used the solution?

    I've been using this solution for four years. 

    What do I think about the scalability of the solution?

    Scalability is good; you just add extra licenses. We have 15 admin users and around 10,000 EPS.

    How was the initial setup?

    There are lots of issues with licensing policies like the agentless and agent-based installation. It creates a lot of issues because when we purchase the SIEM, by default, we expect most of the licenses to be in the bundle. But it's not like that. We need to purchase separate licenses for each agent and agentless system. There is also licensing with the EPS. It's quite difficult for proposing and purchasing the solution. We hire Fortinet professional services for deployment. 

    Which other solutions did I evaluate?

    I think that QRadar and RSE are better solutions than SIEM. The interactivity, scalability, and performance are far better than Fortinet. 

    What other advice do I have?

    My needs are not getting met with this solution so I would not recommend it to anyone and rate it four out of 10. 

    Which deployment model are you using for this solution?

    Private Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer1146195 - PeerSpot reviewer
    Head - IT & SWIFT at a financial services firm with 1-10 employees
    Real User
    Sep 15, 2022
    Good dashboards and customization but issues with licensing
    Pros and Cons
    • "FortiSIEM's best features are the dashboards and customization."
    • "FortiSIEM's stability is quite good."
    • "An improvement would be if FortiSIEM's licensing was based on the number of nodes rather than the EPS."
    • "An improvement would be if FortiSIEM's licensing was based on the number of nodes rather than the EPS."

    What is our primary use case?

    I use FortiSIEM for email events and security alarms.

    What is most valuable?

    FortiSIEM's best features are the dashboards and customization.

    What needs improvement?

    An improvement would be if FortiSIEM's licensing was based on the number of nodes rather than the EPS. In the next release, FortiSIEM should implement a central repository.

    For how long have I used the solution?

    I've been working with FortiSIEM for more than three years.

    What do I think about the stability of the solution?

    FortiSIEM's stability is quite good.

    What do I think about the scalability of the solution?

    FortiSIEM is scalable, though this is constrained by the licensing model.

    How are customer service and support?

    FortiSIEM's technical support is satisfactory, but its knowledge base could be better.

    How would you rate customer service and support?

    Positive

    What about the implementation team?

    We used an in-house team and the local vendor.

    What's my experience with pricing, setup cost, and licensing?

    FortiSIEM's licensing is based on EPS, and its pricing is competitive in the market.

    Which other solutions did I evaluate?

    I also evaluated LogRhythm and McAfee.

    What other advice do I have?

    I would give FortiSIEM a rating of seven out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Presales IT at a tech services company with 201-500 employees
    MSP
    Aug 22, 2022
    Integrates logs from different sources so that there is a common place to see and create dashboards
    Pros and Cons
    • "FortiSIEM helped us discover all the threats at the time that were attacking the IT services of the company. We now have multiple-level authentication."
    • "FortiSIEM helped us discover all the threats at the time that were attacking the IT services of the company."
    • "The process of installing Fortinet FortiSIEM and the customization of the alerts take too long."
    • "The process of installing Fortinet FortiSIEM and the customization of the alerts take too long."

    What is our primary use case?

    I work in our presales department. We have three of our clients using Fortinet FortiSIEM.

    The solution is useful to integrate logs from different sources so that there is a common place to see and create dashboards and the AI associated with event checking.

    We have a common service desk for our customers that has three employees monitoring everything. It requires less than one person to watch the dashboards, send the alerts and call the back office during an event. The solution requires maintenance every three months to install the last stable version of the firmware.

    How has it helped my organization?

    FortiSIEM helped us discover all the threats at the time that were attacking the IT services of the company. We now have multiple-level authentication. We use VPN instead of publishing services to the world, and we closed some services that are no longer being used. Eventually, we geographically blocked some services that do not need to be published in China or the United States, for example.

    What is most valuable?

    FortiSIEM has been a good product. It does everything that it has promised that it can do. It has been very useful to discover new threats from the outside such as external exploits, brute-force, or password tries. 

    What needs improvement?

    The process of installing Fortinet FortiSIEM and the customization of the alerts take too long. You need to customize the alerts that come to the dashboard so that not everything is an alert. If everything is an alert, nothing is an alert. This is a complicated process and takes time.

    In future releases, I would like to see a resource for common environments like VMware and VMware/FortiGate or VMware/Check Point. The resource should discover and speed up implementation.

    For how long have I used the solution?

    We have been using Fortinet FortiSIEM for a year and a half.

    What do I think about the stability of the solution?

    Being a Linux virtual appliance, FortiSIEM is a stable platform.

    What do I think about the scalability of the solution?

    We are located in Uruguay, which is a small country. We have no issues with scalability because we have so few people and our IT infrastructure is quite simple. 

    Our customers have between 200 and 400 users of Fortinet FortiSIEM.

    How are customer service and support?

    I would rate the customer service and support of Fortinet FortiSIEM a four out of five. They are quite good.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Prior to FortiSIEM, we did not use SIEM. We had a log concentrator, but it did not have the ability or the AI to correlate logs like SIEM has.

    We decided to implement FortiSIEM because SIEM has the ability to create logs using AI. With a log concentrator, we have all the events there, but there is no relation between them and what we have to do manually.

    How was the initial setup?

    The initial setup of Fortinet FortiSIEM is easy. The solution is on a virtual appliance that you download and put in the VMworld or on-premise. I would rate the ease of initial setup a five out of five.

    What about the implementation team?

    Deployment and implementation of FortiSIEM took three months due to the tuning and the building of the dashboards. We used Fortinet professional services for our first deployment. For the second deployment, we used our in-house team. 

    What was our ROI?

    We are seeing very good results on a security level.

    What's my experience with pricing, setup cost, and licensing?

    Fortinet's products are not expensive, it is less than the competition. There are additional fees for space in the virtual environment. You require virtual space because the logs take up space on the disk. Eventually, you need to buy disks and put them in your environment or in the cloud. Without the disk, you have to turn off the device.

    I would rate them a three out of five overall for pricing.

    Which other solutions did I evaluate?

    We did consider Sentinel in Azure because it is almost free.

    What other advice do I have?

    If you are considering Fortinet FortiSIEM for your organization, write down what alerts are important to you, which devices deserve to be monitored, and which logs you really need. You will need to customize all of this. If you have all of this detailed, the implementation process will be easier.

    I would rate the solution an eight out of ten overall.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Microsoft Azure
    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    reviewer1905006 - PeerSpot reviewer
    Senior Product Manager at a financial services firm with 201-500 employees
    Real User
    Jul 5, 2022
    Simple implementation, good performance, but scalability lacking
    Pros and Cons
    • "The most valuable feature of Fortinet FortiSIEM is the correlation of many events."
    • "Fortinet FortiSIEM has helped our organization by providing us with business monitoring."
    • "Fortinet FortiSIEM could improve to extend to several locations or sites."
    • "Fortinet FortiSIEM could improve to extend to several locations or sites."

    What is our primary use case?

    I am using Fortinet FortiSIEM to correlate events in our enterprise.

    How has it helped my organization?

    Fortinet FortiSIEM has helped our organization by providing us with business monitoring.

    What is most valuable?

    The most valuable feature of Fortinet FortiSIEM is the correlation of many events.

    What needs improvement?

    Fortinet FortiSIEM could improve to extend to several locations or sites.

    For how long have I used the solution?

    I have been using Fortinet FortiSIEM for approximately two years.

    What do I think about the stability of the solution?

    The stability of Fortinet FortiSIEM is okay but it could improve.

    What do I think about the scalability of the solution?

    We would like to increase the usage of Fortinet FortiSIEM.

    How are customer service and support?

    The technical support from Fortinet FortiSIEM is good.

    Which solution did I use previously and why did I switch?

    We previously used Juniper Security Threat Response Manager.

    How was the initial setup?

    The initial setup of Fortinet FortiSIEM is easy. The full deployment took approximately seven days.

    What about the implementation team?

    We had one supervisor and two others that helped do the implementation of Fortinet FortiSIEM. We did the implementation in-house.

    We have five network administrators for maintenance.

    What was our ROI?

    We have seen a return on investment using Fortinet FortiSIEM.

    What's my experience with pricing, setup cost, and licensing?

    There are additional features that cost more than the standard licensing fees.

    Which other solutions did I evaluate?

    We evaluated two other solutions before choosing Fortinet FortiSIEM. The graphical user interface is better in Fortinet FortiSIEM.

    What other advice do I have?

    I rate Fortinet FortiSIEM a seven out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer1061847 - PeerSpot reviewer
    Research Associate at a comms service provider with 1,001-5,000 employees
    Real User
    Jan 23, 2022
    Good solution for security detection and response
    Pros and Cons
    • "Our customer did not have security monitoring in the first place. With this solution, it provided security posture management and visibility about the security landscape and threats that they had."
    • "Fortinet FortiSIEM combines the SOC and NOC into a single solution with a single pane of glass."
    • "The product does not have Security Orchestration and Automation Response, I would recommend adding this feature."
    • "The product does not have Security Orchestration and Automation Response, I would recommend adding this feature."

    What is our primary use case?

    My company is a partner of Fortinet FortiSIEM. We are a service provider and I take the solution from Fortinet and deploy it for my customers. We use the solution for security detection and response. This is a customer based solution, our customer's security admins and security operations use the solution, compromised of a team between three to five people.

    How has it helped my organization?

    Our customer did not have security monitoring in the first place. With this solution, it provided security posture management and visibility about the security landscape and threats that they had.

    What is most valuable?

    Fortinet FortiSIEM combines the SOC and NOC into a single solution with a single pane of glass. This feature on its own is next level and its easy to handle.

    What needs improvement?

    Fortinet FortiSIEM should consider converting the purchase model from a CapEX investment into a pay-per-use model. By doing this, it will be more attractive for more customers.

    The product does not have Security Orchestration and Automation Response, I would recommend adding this feature.

    For how long have I used the solution?

    I have been using Fortinet FortiSIEM for two years.

    What do I think about the stability of the solution?

    Stability is very good.

    What do I think about the scalability of the solution?

    Fortinet FortiSIEM is scalable.

    How are customer service and support?

    Technical support is perfect.

    How was the initial setup?

    The initial setup of Fortinet FortiSIEM was easy. The deployment took a week and a half and was based on a project plan. You don't need more than two people to deploy and maintain this solution.

    What about the implementation team?

    We use an integrator for the deployment of Fortinet FortiSIEM. 

    What's my experience with pricing, setup cost, and licensing?

    The price of Fortinet FortiSIEM is manageable. The cost is approximately $90,000 on an annual basis.

    What other advice do I have?

    Before fitting the product into your environment, make sure you have the right requirements.

    I would rate Fortinet FortiSIEM a 9 out of 10.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros sharing their opinions.
    Updated: March 2026
    Buyer's Guide
    Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros sharing their opinions.