I use the solution in my company since it provides ease of monitoring. My company uses the product to get reports for our customers and monitoring purposes, as per the customer's preferences.
A scalable product that offers good UI and firewall
Pros and Cons
- "The product's initial setup phase was easy."
- "The stability of the product is an area of concern where improvements are required."
What is our primary use case?
What needs improvement?
At times, I have noticed that Fortinet FortiSIEM suddenly goes down, and because of this, I have to reboot the servers from the engineers. Usually, I have to restart the panel again to get the product functioning. The aforementioned area of concern has been around for a very long time, making it something where improvements are required.
The stability of the product is an area of concern where improvements are required.
ArcSight can provide a detailed report for a year in a PDF format. In Fortinet FortiSIEM, there is a need to put in manual effort to get a detailed report. In Fortinet FortiSIEM, if I get reports for a specific time frame, I have to manually narrow them down by myself, after which I will not be able to get them in a Word or PDF format, which can be challenging.
For how long have I used the solution?
I have been using Fortinet FortiSIEM for a year. My company uses the product for some of our internal purposes.
What do I think about the scalability of the solution?
It is a scalable tool. The product can handle a considerable number of customers.
At the moment, there are only two people in my company who use the solution. In the future, the number of uses may increase, especially if my company has to deal with more customers who want to use Fortinet FortiSIEM.
Buyer's Guide
Fortinet FortiSIEM
September 2026
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,262 professionals have used our research since 2012.
How are customer service and support?
Based on what I heard from my colleagues, the technical support is not bad. My colleagues directly contact the technical support for help.
How was the initial setup?
The product's initial setup phase was easy. I wasn't a part of the deployment process.
What other advice do I have?
In terms of how the tool supports our company's compliance monitoring and reporting practices, I would say that it stems from the fact that Fortinet FortiSIEM is able to serve what our company's customers want while also having the ability to offer solutions, making it quite easy for us to give the customers what they want. The fact that the solution helps my company provide the reports that my customer wants is actually nice. The tool also offers customization ability.
The features of Fortinet FortiSIEM that I find most effective for real-time security event correlation are real-time server connections, which allow me to see all the servers that are online at a particular period of time. The product also shows the threats and bifurcates them into high, medium, and low. The solution has the ability to generate reports easily. The product also provides specific solutions for any threats that are found.
The way Fortinet FortiSIEM improves my company's security posture stems from the fact that with the tool, I can see whatever is happening in real-time. In terms of security issues, if I try to see the problem or threat, then I can really dig deep into what is happening, which is a nice feature.
The tool is easy to maintain. Only two people are required to maintain the solution.
If I compare the integration capabilities of ArcSight with Fortinet FortiSIEM, I would have to say that the latter is in a better position to provide its customers with more details in terms of cybersecurity threats or if they want to compare the firewalls. Fortinet FortiSIEM is better for customers with no cybersecurity knowledge since it helps them understand the product. Fortinet FortiSIEM is better for the security of its customers.
I would ask those who plan to use the Fortinet FortiSIEM to see whether there are other solutions with which it needs to interact in their environment. Fortinet FortiSIEM is one of the best solutions I have dealt with, considering that it has a nice user interface. The update page is good and works in real time. The firewall part of the tool is good. I don't think there is anything that can cause problems for the tool's firewall. I actually liked the tool's firewall.
I rate the overall tool a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Security & CyberSecurity Consultant at digitalDefense Information Systems GmbH
A scalable solution with extensive customization options
Pros and Cons
- "This solution offers extensive customization options, making it possible to adapt it precisely to their requirements."
- "Customer support service could be better."
What is our primary use case?
If a customer is looking to establish a centralized monitoring and security solution, Fortinet FortiSIEM can be tailored to meet their specific needs effectively. This solution offers extensive customization options, making it possible to adapt it precisely to their requirements.
What is most valuable?
It works exceptionally well when combined with a vulnerability management solution.
What needs improvement?
Customer support service could be better.
What do I think about the stability of the solution?
It provides great stability features.
What do I think about the scalability of the solution?
Scalability is excellent, especially for our enterprise-level clients.
How are customer service and support?
I have moderate satisfaction with customer support, and we've learned to manage it adequately. I would rate it three out of ten.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
I previously worked with LogPoint, which had rigid pricing structures. In contrast, we value flexibility and aim to provide more adaptable support, so we switched to Fortinet FortiSIEM.
How was the initial setup?
The initial setup is quite swift.
What about the implementation team?
The deployment process usually takes just one to two days to have the basics up and running. This involves connecting the collectors and configuring the systems.
What's my experience with pricing, setup cost, and licensing?
Pricing is determined based on the customer's budget. We discuss how to tailor the pricing to fit the specific needs and financial considerations of the customer.
What other advice do I have?
I would highly recommend it. It's a top-tier solution, receiving a solid ten out of ten rating.
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Buyer's Guide
Fortinet FortiSIEM
September 2026
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,262 professionals have used our research since 2012.
Principal Solution Architect- Security & Privacy at Sify Technologies
Less costly than other products, but needs more marketing
Pros and Cons
- "Fortinet FortiSIEM is less costly than other products and is available 24/7."
- "Fortinet FortiSIEM is a little out of sight and needs more marketing efforts to be popular in the market."
What is our primary use case?
We have an MSSP license and provide services to customers from various verticals like manufacturing, pharmaceutical, and MRD (Manufacturing, Retail & Distribution). We provide the services of Fortinet FortiSIEM to customers who cannot avail of costly on-premise services.
What is most valuable?
Fortinet FortiSIEM is less costly than other products and is available 24/7.
What needs improvement?
Fortinet FortiSIEM is a little out of sight and needs more marketing efforts to be popular in the market.
For how long have I used the solution?
We have been using Fortinet FortiSIEM for almost one and a half years.
What do I think about the stability of the solution?
The stability of Fortinet FortiSIEM is good.
What do I think about the scalability of the solution?
Fortinet FortiSIEM has good scalability.
How are customer service and support?
I have faced no issues with Fortinet FortiSIEM’s customer support.
How was the initial setup?
The deployment of Fortinet FortiSIEM, which included the migration of 30 plus customers and the initial setup of all components, did not take more than a month.
What's my experience with pricing, setup cost, and licensing?
Fortinet FortiSIEM is cheaper compared to other products.
What other advice do I have?
I use the latest version of Fortinet FortiSIEM. We have deployed Fortinet FortiSIEM on VMware.
Overall, I rate Fortinet FortiSIEM a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer.
Solutions Architect at In2IT Technologies
Useful behavior data monitoring, helpful support, and different deployment methods available
Pros and Cons
- "The most valuable feature of Fortinet FortiSIEM is the user and entity behave as analytics(UEBA). This feature mixes your data and provides useful information based on the behavior of the targeted."
- "The UI could improve in Fortinet FortiSIEM. Humans view the UI frequently for data and if it was more visually pleasing it would be beneficial."
What is our primary use case?
Fortinet FortiSIEM is used to retrieve logs from different sources, such as network switches, firewalls, and servers, that are running difficult operating systems. The solution adds intelligence to the process that can provide meaningful information for the data analyst to use.
The solution can be deployed on the cloud or on-premise.
What is most valuable?
The most valuable feature of Fortinet FortiSIEM is the user and entity behave as analytics(UEBA). This feature mixes your data and provides useful information based on the behavior of the targeted.
What needs improvement?
The UI could improve in Fortinet FortiSIEM. Humans view the UI frequently for data and if it was more visually pleasing it would be beneficial.
For how long have I used the solution?
I have been using Fortinet FortiSIEM for a couple of years.
What do I think about the stability of the solution?
The stability of Fortinet FortiSIEM is stable.
I rate stability Fortinet FortiSIEM an eight out of ten.
What do I think about the scalability of the solution?
Fortinet FortiSIEM is known for its scalability, it scales well.
We have a couple of customers using this solution.
I rate the scalability of Fortinet FortiSIEM a nine out of ten.
How are customer service and support?
The support from Fortinet FortiSIEM is great.
How was the initial setup?
The initial setup is easy, but the time it takes for the deployment depends on the number of applications monitored. One of our clients has taken us three weeks, but a typical setup takes one month. Some logs are simple to configure while others can be more difficult.
Deploying the solution is a straightforward process that involves just a few steps, such as loading the solution and configuring it, after which the solution will commence retrieving the data.
What about the implementation team?
We do the implementation of the solution with two administrators within one month.
What's my experience with pricing, setup cost, and licensing?
The price of the solution is expensive. The license is scalable. If there are 10 devices it is simple to license.
What other advice do I have?
My advice to others that might want to implement this solution is to know their business needs. There are other solutions, such as Splunk that can provide a lot more information when collecting data but it might not be needed for their use case. A small business would not need all the extra features of Splunk.
I rate Fortinet FortiSIEM an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Solution Architect at Tiger IT Bangladesh Limited
The solution's ability to collect data from different sources is its most valuable feature
Pros and Cons
- "It works well with medium to large-scale enterprises."
- "They should enhance the solution's AI capabilities, including XDR and EDR."
What is most valuable?
The solution's ability to collect data from different sources is its most valuable feature.
What needs improvement?
They should enhance the solution's AI capabilities, including XDR and EDR.
For how long have I used the solution?
We have been using the solution for six months.
What do I think about the stability of the solution?
I rate the solution's stability as a nine.
What do I think about the scalability of the solution?
I rate the solution's scalability as an eight. It works well with medium to large-scale enterprises.
How are customer service and support?
The solution's tech support team is good.
How was the initial setup?
The solution's initial setup is a bit complex as you have to do a lot of configuration. You have to collect data from different sources such as Microsoft, IBM, etc. The data extraction process differs for every system. Thus, you have to apply different protocols to collect data from various sources.
What other advice do I have?
The solution has a lot of network solutions in its bucket. As a result, they provide excellent network strength. I advise others to know the product well before implementing it. I rate it as an eight.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Network Security Engineer at Technicom Mali
A simple setup but needs better visibility and more correlation tools
Pros and Cons
- "It is used as an alerting platform."
- "If you don't have a dedicated team to handle your logs, don't have a big budget, and want a solution to correlate and collect logs from many vendors, Fortinet FortiSIEM is an excellent choice."
- "The log collection and configuration management are not great."
What is our primary use case?
It is used as an alerting platform and has an availability manager.
What is most valuable?
We already have experience with Fortinet products, so dealing with Fortinet FortiSIEM is not complicated.
What needs improvement?
They should offer better visibility, more correlation tools and a better understanding of the network. Fortinet FortiSIEM already uses simple and standard protocols like SNMP, DuraMI and Syslog. Other solutions like QRadar use sFlow, so I think that they can do better.
In addition, the log collection and configuration management are not great.
For how long have I used the solution?
We have been using this solution for three years. We deployed Fortinet FortiSIEM at about three customer sites, and it is deployed on-premises.
What do I think about the stability of the solution?
The product is stable.
What do I think about the scalability of the solution?
It is a scalable solution.
How are customer service and support?
We have expertise with the product, so we don't use technical support often. We only require support for the error mark, and the support is quick and fast for that.
How was the initial setup?
The initial setup was simple, and we deployed Fortinet FortiSIEM in two days. We already had all the information regarding the customers' notes, and it was simple, quick and fast.
What's my experience with pricing, setup cost, and licensing?
It is cheaper than LogPoint or QRadar.
What other advice do I have?
I rate this solution a five out of ten. It is not as good as other solutions like QRadar, but it's cheaper than other products and very simple. In the next release, the visibility should consist of simple and standard protocols.
Regarding advice, if you don't have a dedicated team to handle your logs, don't have a big budget, and want a solution to correlate and collect logs from many vendors, Fortinet FortiSIEM is an excellent choice.
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Head - IT & SWIFT at a financial services firm with 1-10 employees
Good dashboards and customization but issues with licensing
Pros and Cons
- "FortiSIEM's best features are the dashboards and customization."
- "FortiSIEM's stability is quite good."
- "An improvement would be if FortiSIEM's licensing was based on the number of nodes rather than the EPS."
What is our primary use case?
I use FortiSIEM for email events and security alarms.
What is most valuable?
FortiSIEM's best features are the dashboards and customization.
What needs improvement?
An improvement would be if FortiSIEM's licensing was based on the number of nodes rather than the EPS. In the next release, FortiSIEM should implement a central repository.
For how long have I used the solution?
I've been working with FortiSIEM for more than three years.
What do I think about the stability of the solution?
FortiSIEM's stability is quite good.
What do I think about the scalability of the solution?
FortiSIEM is scalable, though this is constrained by the licensing model.
How are customer service and support?
FortiSIEM's technical support is satisfactory, but its knowledge base could be better.
How would you rate customer service and support?
Positive
What about the implementation team?
We used an in-house team and the local vendor.
What's my experience with pricing, setup cost, and licensing?
FortiSIEM's licensing is based on EPS, and its pricing is competitive in the market.
Which other solutions did I evaluate?
I also evaluated LogRhythm and McAfee.
What other advice do I have?
I would give FortiSIEM a rating of seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Assistant to Vice President at IT Green Public Company Limited
Plenty of features, good support, but lacking signature updates
Pros and Cons
- "The most valuable features of Fortinet FortiSIEM are the SD-WAN, Global LAN, and application controls."
- "I would advise others this solution is easy to use and has a lot of features."
- "Fortinet FortiSIEM could improve by having a signature update."
What is our primary use case?
We use Fortinet FortiSIEM for security, a gateway, and for authentication.
What is most valuable?
The most valuable features of Fortinet FortiSIEM are the SD-WAN, Global LAN, and application controls.
What needs improvement?
Fortinet FortiSIEM could improve by having a signature update.
For how long have I used the solution?
I have been using Fortinet FortiSIEM for approximately 16 years.
What do I think about the stability of the solution?
Fortinet FortiSIEM is stable. However, it was not stable from the beginning.
What do I think about the scalability of the solution?
Fortinet FortiSIEM is the best soltuions here in Thailand. There are many users and partners here.
There are 10 to 3,000 users in my company. Most of the users are specialists in IT. We plan to increase usage in the future.
How are customer service and support?
I have used the technical support and they have been good.
Which solution did I use previously and why did I switch?
I have used other solutions previously.
How was the initial setup?
The initial setup of Fortinet FortiSIEM was easy. The deployment would take a few days for the middle and large models.
We need some information for the customer, such as policies, before we can implement the solution.
What about the implementation team?
We do the implementation of Fortinet FortiSIEM. We use one IT specialist for the deployment and maintenance of the solution.
What other advice do I have?
I would advise others this solution is easy to use and has a lot of features. They should try it out.
I rate Fortinet FortiSIEM a seven out of ten
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Senior Security Engineer at a tech services company with 1,001-5,000 employees
It's a nice tool for integration and monitoring, but it's difficult to integrate unsupported devices
Pros and Cons
- "FortiSIEM provides a single PIN to monitor SOC and NOC. It's a nice tool for integration and monitoring. It provides multiple categories for monitoring based on security designations like low, medium, and high."
- "It's difficult to integrate unsupported devices with FortiSIEM compared to QRadar. It's easier to integrate and develop processes in QRadar. It's harder to develop a custom process in FortiSIEM."
What is our primary use case?
We have nearly 30 analysts currently using FortiSIEM.
What is most valuable?
FortiSIEM provides a single PIN to monitor SOC and NOC. It's a nice tool for integration and monitoring. It provides multiple categories for monitoring based on security designations like low, medium, and high.
What needs improvement?
It's difficult to integrate unsupported devices with FortiSIEM compared to QRadar. It's easier to integrate and develop processes in QRadar. It's harder to develop a custom process in FortiSIEM.
For how long have I used the solution?
I've been using FortiSIEM for a year and a half.
What do I think about the stability of the solution?
FortiSIEM is stable. QRadar and FortiSIEM are both fairly stable. There aren't many issues from an admin point of view.
What do I think about the scalability of the solution?
FortiSIEM is scalable.
How are customer service and support?
Fortinet support is great. They're more responsive than IBM.
How was the initial setup?
FortiSIEM is easy to set up. Installing the supervisor component of FortiSIEM took around one hour, but the console installation for QRadar takes almost three to four hours.
What other advice do I have?
I rate FortiSIEM seven out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Product Manager at a financial services firm with 201-500 employees
Simple implementation, good performance, but scalability lacking
Pros and Cons
- "The most valuable feature of Fortinet FortiSIEM is the correlation of many events."
- "Fortinet FortiSIEM has helped our organization by providing us with business monitoring."
- "Fortinet FortiSIEM could improve to extend to several locations or sites."
What is our primary use case?
I am using Fortinet FortiSIEM to correlate events in our enterprise.
How has it helped my organization?
Fortinet FortiSIEM has helped our organization by providing us with business monitoring.
What is most valuable?
The most valuable feature of Fortinet FortiSIEM is the correlation of many events.
What needs improvement?
Fortinet FortiSIEM could improve to extend to several locations or sites.
For how long have I used the solution?
I have been using Fortinet FortiSIEM for approximately two years.
What do I think about the stability of the solution?
The stability of Fortinet FortiSIEM is okay but it could improve.
What do I think about the scalability of the solution?
We would like to increase the usage of Fortinet FortiSIEM.
How are customer service and support?
The technical support from Fortinet FortiSIEM is good.
Which solution did I use previously and why did I switch?
We previously used Juniper Security Threat Response Manager.
How was the initial setup?
The initial setup of Fortinet FortiSIEM is easy. The full deployment took approximately seven days.
What about the implementation team?
We had one supervisor and two others that helped do the implementation of Fortinet FortiSIEM. We did the implementation in-house.
We have five network administrators for maintenance.
What was our ROI?
We have seen a return on investment using Fortinet FortiSIEM.
What's my experience with pricing, setup cost, and licensing?
There are additional features that cost more than the standard licensing fees.
Which other solutions did I evaluate?
We evaluated two other solutions before choosing Fortinet FortiSIEM. The graphical user interface is better in Fortinet FortiSIEM.
What other advice do I have?
I rate Fortinet FortiSIEM a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Popular Comparisons
Splunk Enterprise Security
SentinelOne Singularity Cloud Security
SentinelOne Singularity Endpoint
Dynatrace
IBM Security QRadar
Microsoft Sentinel
Elastic Security
LogRhythm SIEM
Rapid7 InsightIDR
Cortex XSIAM
Gigamon Deep Observability Pipeline
Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?
- What Questions Should I Ask Before Buying SIEM?
- What are the pros and cons of internal SOC vs SOC-as-a-Service?



















