We use Fortinet FortiSIEM for security, a gateway, and for authentication.
Assistant to Vice President at IT Green Public Company Limited
Plenty of features, good support, but lacking signature updates
Pros and Cons
- "The most valuable features of Fortinet FortiSIEM are the SD-WAN, Global LAN, and application controls."
- "I would advise others this solution is easy to use and has a lot of features."
- "Fortinet FortiSIEM could improve by having a signature update."
What is our primary use case?
What is most valuable?
The most valuable features of Fortinet FortiSIEM are the SD-WAN, Global LAN, and application controls.
What needs improvement?
Fortinet FortiSIEM could improve by having a signature update.
For how long have I used the solution?
I have been using Fortinet FortiSIEM for approximately 16 years.
Buyer's Guide
Fortinet FortiSIEM
June 2026
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
902,270 professionals have used our research since 2012.
What do I think about the stability of the solution?
Fortinet FortiSIEM is stable. However, it was not stable from the beginning.
What do I think about the scalability of the solution?
Fortinet FortiSIEM is the best soltuions here in Thailand. There are many users and partners here.
There are 10 to 3,000 users in my company. Most of the users are specialists in IT. We plan to increase usage in the future.
How are customer service and support?
I have used the technical support and they have been good.
Which solution did I use previously and why did I switch?
I have used other solutions previously.
How was the initial setup?
The initial setup of Fortinet FortiSIEM was easy. The deployment would take a few days for the middle and large models.
We need some information for the customer, such as policies, before we can implement the solution.
What about the implementation team?
We do the implementation of Fortinet FortiSIEM. We use one IT specialist for the deployment and maintenance of the solution.
What other advice do I have?
I would advise others this solution is easy to use and has a lot of features. They should try it out.
I rate Fortinet FortiSIEM a seven out of ten
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Cybersecurity Engineer at a tech services company with 11-50 employees
Stable machine learning solution that offers the advanced use of AI
Pros and Cons
- "The advanced agents used to collect logs have been most valuable. We have also made use of the advanced intelligence this solution offers."
- "The graphs on the user interface could be improved as we often experience glitches."
- "The customer service team needs additional experience and knowledge of the solution so the answers they provide are more accurate and helpful."
What is our primary use case?
We use this solution to collect logs.
What is most valuable?
The advanced agents used to collect logs have been most valuable. We have also made use of the advanced intelligence this solution offers.
What needs improvement?
The graphs on the user interface could be improved as we often experience glitches.
What do I think about the stability of the solution?
This is a stable solution.
How are customer service and support?
The customer service team needs additional experience and knowledge of the solution so the answers they provide are more accurate and helpful.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We use this solution together with McAfee ESM which is a simple and robust solution. Its interface is better than SIEM.
How was the initial setup?
The initial setup was straightforward. The time it takes to complete the setup and deployment depends on the size of the environment and the number of EPS events per second.
What other advice do I have?
This is a good solution but is fairly new so the support for it is not effective. Their support team does not have the experience to immediately solve issues.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Fortinet FortiSIEM
June 2026
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
902,270 professionals have used our research since 2012.
Technical manager at a tech services company with 11-50 employees
User-friendly, reliable scales well, and has good technical support
Pros and Cons
- "Fortinet FortiSIEM is easy to use."
- "I would like to see more integration with other platforms."
What is our primary use case?
This solution is used to detect irregular user and entity behavior using machine learning.
What is most valuable?
Fortinet FortiSIEM is easy to use.
What needs improvement?
I would like to see more integration with other platforms.
For how long have I used the solution?
We have been providing Fortinet FortiSIEM for one year.
This solution can be deployed both on Cloud, and on-premises.
What do I think about the stability of the solution?
Fortinet FortiSIEM is a stable solution.
What do I think about the scalability of the solution?
It's a scalable product.
How are customer service and support?
Technical support is good enough. They were able to help us.
How was the initial setup?
It is easy to install.
In one day, we were able to install this solution ourselves.
We only need one engineer to maintain this solution.
What's my experience with pricing, setup cost, and licensing?
They have a yearly subscription.
What other advice do I have?
I would rate Fortinet FortiSIEM a ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Assistant Engineer at Harel Mallac Technologies Ltd
Easy to use, user-friendly, and reliable
Pros and Cons
- "The solution is easy to use and user-friendly."
- "Fortinet FortiSIEM could improve by having better integration and extensions. This would benefit by allowing us to give more rules."
What is our primary use case?
Fortinet FortiSIEM can be used to detect unusual user and entity behavior on networks.
We currently are in the process of testing the solution.
What is most valuable?
The solution is easy to use and user-friendly.
What needs improvement?
Fortinet FortiSIEM could improve by having better integration and extensions. This would benefit by allowing us to give more rules.
For how long have I used the solution?
I have been using Fortinet FortiSIEM for a few months.
What do I think about the stability of the solution?
I have found Fortinet FortiSIEM to be stable.
What do I think about the scalability of the solution?
Fortinet FortiSIEM is scalable.
How was the initial setup?
The installation is straightforward and can be done in one day.
What about the implementation team?
I am able to do the implementation of the solution.
What's my experience with pricing, setup cost, and licensing?
The solution is available for both, perpetual and subscription licenses.
What other advice do I have?
I rate Fortinet FortiSIEM an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Security Engineer L1 at a media company with 11-50 employees
Easy to understand and the technical support is good, but they need better documentation
Pros and Cons
- "It's a very nice solution to work with."
- "There is no proper guide for integration or configuration. They need to improve the documentation library."
What is our primary use case?
We are trying to onboard some devices, which we will analyze using Fortinet FortiSIEM.
Once it responds smoothly, we will onboard some clients with requests.
What is most valuable?
It's a very nice solution to work with. It is easy to understand.
What needs improvement?
There is no proper guide for integration or configuration. They need to improve the documentation library.
For how long have I used the solution?
We are using the enterprise version in my organization. I have been using it for 30 to 40 days, but not more than two months.
How are customer service and technical support?
We have contacted technical support. They are good and provide good resolutions.
How was the initial setup?
The initial setup was straightforward.
What other advice do I have?
I will definitely recommend this solution to others. I am still exploring it, as it is new to us. I need more time to analyze it further.
I would rate Fortinet FortSIEM a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Chief Technical Officer at a computer software company with 51-200 employees
Beneficial CMDB and device discovery, but implementation process needs improvement
Pros and Cons
- "The CMDB and the device discovery features are most valuable."
- "I would like to see easier implementation in the future."
- "The initial setup is not simple. We are having some issues with the agent installation, it is requiring several reboots."
What is most valuable?
The CMDB and the device discovery features are most valuable.
What needs improvement?
I would like to see easier implementation in the future.
For how long have I used the solution?
I have been using the solution for approximately five months.
What do I think about the scalability of the solution?
Most of our clients are medium-sized businesses.
How are customer service and technical support?
The technical support has been very good in helping us with issues we have been facing during the implementation of the solution. We are not finished yet but we are close.
How was the initial setup?
The initial setup is not simple.
We are having some issues with the agent installation, it is requiring several reboots. This could be the system environment at the client site because in our lab the agent installation is straightforward and it does not require reboots. We are still working on this issue.
What about the implementation team?
We are doing the implantation of the solution and it has a moderate level of difficulty.
What other advice do I have?
I rate Fortinet FortiSIEM a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
Partner at a security firm with 11-50 employees
Good network monitoring with excellent scalability and good stability
Pros and Cons
- "The stability is very reliable. It offers very good performance."
- "The network monitoring is one of the most valuable aspects of the solution."
- "The policy editing should be easier. Right now, it's too hard."
- "The initial setup is complex. They need to make it easier in terms of implementation."
What is our primary use case?
We primarily use the solution for network and security monitoring.
What is most valuable?
Most of those CM functions and the correlation alerts are very helpful to our clients.
The network monitoring is one of the most valuable aspects of the solution.
You can scale the solution with ease if you need to expand.
The stability is very reliable. It offers very good performance.
What needs improvement?
The initial setup is complex. They need to make it easier in terms of implementation. That said, all CM implementations are quite difficult. It may not be a fault of this particular product.
The policy editing should be easier. Right now, it's too hard.
Some of the parts of the mapping tool should be in the product itself. It would make our efforts easier.
The product is quite expensive. It's something clients always comment on.
For how long have I used the solution?
We have been using the solution for many years - including before Fortinet acquired the original organization.
What do I think about the stability of the solution?
The solution is quite stable. We find it very reliable. It doesn't crash or freeze. There aren't bugs and glitches.
What do I think about the scalability of the solution?
The scalability of the solution is excellent. It's one of the main reasons we chose to go with this option. If a company needs to expand, it can do so easily. There aren't constraints.
We have about five to ten customers on the solution currently.
How are customer service and technical support?
I'm not using the vendor's technical support. Mostly we have our own in-house resources. I cannot tell if are they good or bad. I have never dealt directly with them. Therefore, it would be difficult to review their services.
How was the initial setup?
In terms of the initial setup, the process is not straightforward. It's complex and difficult. Making it easier would help a lot.
All CM installations and implementations are complicated. You have to tailor the product. It's not really something you can just implement out-of-the-box.
That said, a basic installation is simple. It takes a few days. After you've done the implementation stage, then it takes time. Of course, it depends on the projects. I cannot say how much time it's taken exactly. I just know it takes quite a while.
For deployment, we use two people in a project. One of them is for the beginning of the project - for the implementation and the installation process. The other is the administration which we are generally pas off to our customers. I tend to handle the daily operations.
What's my experience with pricing, setup cost, and licensing?
All of our customers find the solution expensive. It's not a cheap option.
I don't know the exact cost of the solution as I don't directly handle the licensing.
What other advice do I have?
We are actually a reseller service company and we are dealing with the solutions for our customers. We are using the SIEM solutions. We are not a user, we are a reseller.
We have many customers. Not all may be using the latest version of the solution.
I would recommend the solution.
In general, I would rate the solution eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
chief of cybersecurity at ECSSA El Salvador
Allows us to combine SOC and NOC operations and has good reports, integrations, and support
Pros and Cons
- "One of the most valuable features is that we can combine SOC and NOC operations in the same tool. We can provide NOC and SOC services in the same tool for two separate teams. There are plenty of third-party solutions that integrate with FortiSIEM. All these solutions already have a ready integration, and we have the possibility to create a custom connector for these solutions. Its reports are also very good."
- "With the help of FortiSIEM we have improved the cybersecurity posture of our clients and ours, and through the early detection of threats, it allows us to follow up on each security incident and easily communicate to asset managers about related security events, reducing remediation time."
- "Its training can be improved. Its price also needs to be improved."
What is our primary use case?
We are an enterprise that resells services. We are like a small MSSP for Salvador and Central America region. We provide services to other enterprises.
Our clients have multiple use cases. Its most common use case to detect logging events from different IP addresses or locations. It is used to detect simultaneous logins by the same user from different IP addresses or locations, such as from different countries. It is also used to detect any attempts to log in to a server with root privilege and trying remote access with root privileges.
How has it helped my organization?
With the help of FortiSIEM we have improved the cybersecurity posture of our clients and ours. Through the early detection of threats, it allows to follow up on each security incident. It is easy to communicate to asset managers about related security events, reducing remediation time.
What is most valuable?
One of the most valuable features is that we can combine SOC and NOC operations in the same tool. We can provide NOC and SOC services in the same tool for two separate teams.
There are plenty of third-party solutions that integrate with FortiSIEM. All these solutions already have a ready integration, and we have the possibility to create a custom connector for these solutions. Its reports are also very good.
What needs improvement?
Its training can be improved. Its price also needs to be improved.
For how long have I used the solution?
I have been using this solution for one year.
What do I think about the stability of the solution?
It has been good so far. We don't have any complaints about the tool.
What do I think about the scalability of the solution?
It is very scalable. It is easy to grow with this tool. We are going step-by-step, and we are doing good so far.
Our clients are big enterprises, such as banks, and we also have small businesses. In Salvador, as per a local compliance requirement, every business or enterprise needs to have a SIEM solution. We have an installation for 1,000 users.
How are customer service and technical support?
We are Fortinet's partner here in Salvador, and the tech support is really good. Their response time is also really good. We are very happy with this solution.
How was the initial setup?
The implementation process is kind of easy. We start in a small way. The challenge for us is the storage. We need to find a way to have storage redundancy so that if the main site fails, we have a copy of the data on a remote site. This is the challenge that we are facing right now.
What about the implementation team?
For its deployment and maintenance, we have a very small group of five people. We have a networking guy, a server guy, and a few analysts to maintain this platform.
What's my experience with pricing, setup cost, and licensing?
There is a licensing scheme for every case. There are three licensing schemes that we can choose from.
Which other solutions did I evaluate?
Our clients also evaluate other solutions such as Rapid7, McAfee, and LogRhythm. We have always been a Fortinet enterprise. We have people with Fortinet and other certifications in the industry, such as EasyConsole certifications. We can also support this solution for the Fortinet sites. That is the main differentiator between us and other vendors.
What other advice do I have?
I would advise others to start small and plan for future growth.
I would rate Fortinet FortiSIEM an eight out of ten.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Security Analyst at netfiniti
Good GUI, helpful technical support, and easy to configure
Pros and Cons
- "The product is quite well-organized. The GUI makes it easy to navigate."
- "If you are comparing the product to Cisco's solutions, it's very cheap and moderately priced, it's affordable and at the same time a very effective solution that works well."
- "It would be good if the solution offered even more configuration options, especially in relation to the VPN so that it continues to be a very flexible option."
- "The stability of the product is fairly good. It's likely 70-80% there in terms of stability."
What is our primary use case?
I primarily use the solution as part of the firewall. I work mostly with banks and have extensive experience with configuring the VPN in relation to Fortinet.
What is most valuable?
The solution is quite user-friendly.
It's very easy to configure everything, including the VPN. It gives you lots of good options.
The product is quite well-organized. The GUI makes it easy to navigate.
What needs improvement?
The solution is almost 100% perfect. It's already quite simple and easy to configure. In that sense, no improvements are needed.
You do seem to be constantly learning new things with the product. There's a bit of an ongoing learning curve in terms of usage. Right now, I'm learning about higher availability and that's an ongoing process.
It would be good if the solution offered even more configuration options, especially in relation to the VPN so that it continues to be a very flexible option.
The solution offers both command line and GUI visualizations. They need to ensure that their GUI offers just as much flexibility on the configuration as the command line structure.
For how long have I used the solution?
I've been using the solution for about seven months at this point. It's been less than a year.
What do I think about the stability of the solution?
The stability of the product is fairly good. It's likely 70-80% there in terms of stability. There are many versions and the stability may vary slightly on each.
In terms of security, however, I would say it's very stable.
We haven't implemented the latest version yet as it hasn't been implemented widely.
In general, the stability isn't a problem for us and we don't need to worry too much about it.
How are customer service and technical support?
The technical support is quite fine. We can communicate with them easily if we need to. If we have a problem or we need an issue addressed, we simply open a ticket and the Fortinet team is ready to assist. They are very knowledgeable and responsive. We've been satisfied with the support they give us.
How was the initial setup?
The initial setup does take some time to learn. I'm in the process of learning more about it now, specifically in relation to configuration or the VPN.
What's my experience with pricing, setup cost, and licensing?
If you are comparing the product to Cisco's solutions, it's very cheap and moderately priced. It's affordable. At the same time, it's a very effective solution. It's affordable and it works well.
What other advice do I have?
On a scale from one to ten, I would rate the product at an eight. It's been a pretty positive experience overall. I'm still learning the solution and discovering new things about it, however, it has everything I need at the same time.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Programmer Data Center at a consultancy with 10,001+ employees
Stable and pretty affordable
Pros and Cons
- "We find the solution to be stable."
- "There's a great feature on the solution that allows us to analyze security issues and incidents."
- "The solution needs to do a better job with third party integration. Right now, that's lacking on the solution. I specifically am talking about the AWS environment. Most of the AWS environment products do not have that capability to integrate."
What is our primary use case?
We primarily use it for all of our cloud space and for firewalls,and AWS security services etc., for example, for the email, Cloud watch and AWS security HUB
How has it helped my organization?
Single pane of glass for security issues
What is most valuable?
There's a great feature on the solution that allows us to analyze security issues and incidents. It automatically allows us to trace any incident. It's an invaluable aspect of the solution.
The solution has a relatively low cost.
We find the solution to be stable.
It's my understanding that the solution can scale well.
What needs improvement?
The solution needs to be form flow diagram automatically with AWS platform
For how long have I used the solution?
I've only been using the solution for the last six months.
What do I think about the stability of the solution?
The solution is stable. It's very reliable. There aren't bugs or glitches. It doesn't freeze or crash.
What do I think about the scalability of the solution?
I personally have never tried to scale the solution. That said, the solution is scalable and companies shouldn't have any issue expanding it as needed.
The solution is being used pretty extensively in our organization and we have several teams on it.
How are customer service and technical support?
We've definitely called technical support in the past when we have run into issues. We've been satisfied with the level of service they provide. We always get a proper response and they're always ready to resolve any issues we have. We are able to close tickets very quickly because they are so knowledgeable and responsive.
How was the initial setup?
The solution was fairly complex. However, this was due to the fact that we had to do a lot of configurations at the outset. The solution didn't make the process easy for us. Typically, it's easy to implement and I would be able to handle the process myself.
It took us about 15 days to deploy everything on our end.
What about the implementation team?
Implementation was done by Fortinet's Professional Service Team which was quite satisfactorily
What's my experience with pricing, setup cost, and licensing?
The solution is very cost-effective compared to competitors. We just need to pay licensing and support costs. There aren't added costs beyond that.
Which other solutions did I evaluate?
We didn't previously look at other solutions. We saw that Fortinet fit our needs, and therefore we chose it.
What other advice do I have?
We're a public utility, so we just use the solution. We don't have a business relationship with the company.
We use the latest version of the solution.
We use a variety of Fortinet solutions at our organization. For example, we integrate the complete AWS cloud space into that all FortiSIEM.
I'd recommend the solution to other organizations, especially those that are cost-conscious. Compared to there solutions' it's rather easy to implement.
I'd rate the solution overall seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Popular Comparisons
CrowdStrike Falcon
SentinelOne Singularity Cloud Security
Splunk Enterprise Security
SentinelOne Singularity Endpoint
IBM Security QRadar
Microsoft Sentinel
Elastic Security
LogRhythm SIEM
Rapid7 InsightIDR
Cortex XSIAM
Gigamon Deep Observability Pipeline
Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?
- What Questions Should I Ask Before Buying SIEM?
- What are the pros and cons of internal SOC vs SOC-as-a-Service?















