Try our new research platform with insights from 80,000+ expert users
reviewer1051230 - PeerSpot reviewer
Asst Programmer Data Center at a consultancy with 10,001+ employees
Real User
Stable and pretty affordable
Pros and Cons
  • "We find the solution to be stable."
  • "The solution needs to do a better job with third party integration. Right now, that's lacking on the solution. I specifically am talking about the AWS environment. Most of the AWS environment products do not have that capability to integrate."

What is our primary use case?

We primarily use it for all of our cloud space and for firewalls,and AWS security services etc., for example, for the email, Cloud watch and AWS security HUB

How has it helped my organization?

Single pane of glass for security issues

What is most valuable?

There's a great feature on the solution that allows us to analyze security issues and incidents. It automatically allows us to trace any incident. It's an invaluable aspect of the solution. 

The solution has a relatively low cost.

We find the solution to be stable.

It's my understanding that the solution can scale well.

What needs improvement?

The solution needs to be form flow diagram automatically with AWS platform

Buyer's Guide
Fortinet FortiSIEM
August 2025
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
866,218 professionals have used our research since 2012.

For how long have I used the solution?

I've only been using the solution for the last six months.

What do I think about the stability of the solution?

The solution is stable. It's very reliable. There aren't bugs or glitches. It doesn't freeze or crash.

What do I think about the scalability of the solution?

I personally have never tried to scale the solution. That said, the solution is scalable and companies shouldn't have any issue expanding it as needed.

The solution is being used pretty extensively in our organization and we have several teams on it.

How are customer service and support?

We've definitely called technical support in the past when we have run into issues. We've been satisfied with the level of service they provide. We always get a proper response and they're always ready to resolve any issues we have. We are able to close tickets very quickly because they are so knowledgeable and responsive.

How was the initial setup?

The solution was fairly complex. However, this was due to the fact that we had to do a lot of configurations at the outset. The solution didn't make the process easy for us. Typically, it's easy to implement and I would be able to handle the process myself.

It took us about 15 days to deploy everything on our end.

What about the implementation team?

Implementation was done by Fortinet's Professional Service Team which was quite satisfactorily 

What's my experience with pricing, setup cost, and licensing?

The solution is very cost-effective compared to competitors. We just need to pay licensing and support costs. There aren't added costs beyond that.

Which other solutions did I evaluate?

We didn't previously look at other solutions. We saw that Fortinet fit our needs, and therefore we chose it.

What other advice do I have?

We're a public utility, so we just use the solution. We don't have a business relationship with the company.

We use the latest version of the solution.

We use a variety of Fortinet solutions at our organization. For example, we integrate the complete AWS cloud space into that all FortiSIEM.

I'd recommend the solution to other organizations, especially those that are cost-conscious. Compared to there solutions' it's rather easy to implement.

I'd rate the solution overall seven out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
IT Executive: Operations & Security at Icon Information Systems (Pty) Ltd
Real User
The performance is very good, and it is extremely scalable
Pros and Cons
  • "To add workers and even collectors is pretty easy."
  • "The dashboard needs to improve."

What is our primary use case?

We run a Manage Security Services company and we use it in-house and for some of our clients. The service is a multitenant platform where our clients can log on to view and access various security-related activities and features. In more ways, it becomes like a cloud solution to them. We make use of a secure connection from the clients’ networks using collectors located on their premises back to our centralized SIEM platform.

What is most valuable?

The most valuable feature is the differentiator, which has a combination of not only the SOC which covers the security operations aspect, but it also includes NOC capabilities. FortiSIEM uses PAM (Performance, Availability, and Monitoring) from an NOC perspective. So not only do you natively look at security data as most SIEM solutions, but you're also looking at the performance and the availability component of those devices. It's easy for us to coordinate if a security incident occurs. You're not only looking at security logs but you also looking at what could potentially have happened in terms of device performance. So that feature to me already makes it quite a big differentiator in the market, compared to other SIEM tools out there.

What needs improvement?

When they started out after acquiring AccelOps, the user interface wasn't that great. But from version 5.0 they have obviously radically changed the interface, aligning it to the rest of the Forti products from a user experience point of view. This means that there is constant improvement on the interface side of the solution. The other thing that I've noticed is when searching for very old incidents, there is a slight delay. It obviously has to pull that information from the backend database, and the key point to note is that it depends on how you set it up in the backend where factors such as disk types and disk array configs come into play.

For how long have I used the solution?

I have been using this solution for 18 months now.

What do I think about the stability of the solution?

The solution is quite solid and stable.

What do I think about the scalability of the solution?

The scalability component is easy. To add workers and even collectors is easy which is how we've deployed it, makes scalability much easier. We plan to grow our users into the thousands.

How are customer service and technical support?

I never really used support from Fortinet for the FortiSIEM solution that frequent because I figured most of the stuff out on my own, but that being said, the Fortinet Support is great because I figured most of the stuff out on my own.

How was the initial setup?

The initial setup was quite complex. We've had some issues with the first OVF file that we downloaded. We had to customize the installation processes. It was a bit complex in the earlier versions, but the newer versions have greatly improved. 

What other advice do I have?

We use an on-premises deployment model from our perspective and a hybrid model from a customer/user perspective.

I will recommend this solution to others out there looking for a SIEM solution. I've already done a few events we were talk about FortiSIEM and its advantages. I do, however, think the main dashboard where you create and design your graphs could do with some improvement improved. On a scale from 1 to 10, I will rate this solution an 8 to ensure there’s continuous improvement.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Fortinet FortiSIEM
August 2025
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
866,218 professionals have used our research since 2012.
Security Manager at BKL
Real User
Seamless integration with FortiGate, and has an easy setup, but is lacking user behavior analytics
Pros and Cons
  • "The seamless integration with FortiGate is the solution's most valuable aspect."
  • "When compared with some competitors, in terms of performance, the CPU and RAM requirements and the capability of coordination with development all need some improvement."

What is our primary use case?

We primarily use the solution for integration with FortiGate Firewall. We use it for multiple authentification, malware detection, and protection from DDoS attacks.

What is most valuable?

The seamless integration with FortiGate is the solution's most valuable aspect.

What needs improvement?

When compared with some competitors, in terms of performance, the CPU and RAM requirements and the capability of coordination with development all need some improvement.

The solution should offer user behavior analytics in a future release.

For how long have I used the solution?

I've been using the solution for two years.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

We don't have any expansion requirements, so I've never looked into scalability.

How are customer service and technical support?

We've never reached out to technical support. If we need assistance, we typically look for FortiGate documents or scan their blog site. We handle any problems internally.

Which solution did I use previously and why did I switch?

We previously used an open-source solution called Elastic.

How was the initial setup?

The initial setup is easy.

What about the implementation team?

We received support from an integrator.

Which other solutions did I evaluate?

We evaluated AlienVault and SolarWinds. These were both within our limited budget, but we chose FortiSIEM because it integrated seamlessly with FortiGate firewall.

What other advice do I have?

We use the on-premises deployment model.

I'd recommend this solution to companies that have a FortiGate firewall and are on a limited budget. 

I'd rate the solution six out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Solutionbff1 - PeerSpot reviewer
Solutions Consultant at a comms service provider with 51-200 employees
Consultant
A stable solution with good pricing, but they need to address recent changes to technical support
Pros and Cons
  • "Both the collecting logs and duo correlation are valuable features for us."
  • "The support of the product changed recently, and I don't think it's for the better. They should work to improve the support they offer to clients."

What is our primary use case?

We primarily use the solution for collecting logs and duo correlation on our customer's premises.

What is most valuable?

Both the collecting logs and duo correlation are valuable features for us.

Fortinet also offers very good pricing. Their pricing is incredible.

What needs improvement?

The support of the product changed recently, and I don't think it's for the better. They should work to improve the support they offer to clients.

They also have to improve their import perfection solution.

For how long have I used the solution?

I've been using the solution for 1.5 years.

What do I think about the stability of the solution?

The solution is very stable, like all Fortinet products.

What do I think about the scalability of the solution?

The solution is scalable.

How are customer service and technical support?

Technical support is very good. They also provide you with additional materials to study the product by yourself so that you can get a better understanding of the full solution.

How was the initial setup?

The initial setup is complex, mostly because of the security, not because of the product. Most of the security features in the installation process are difficult. They require tuning.  You have to be careful you don't configure something wrong. This is a complexity of the environment and the solution itself. The engineer should understand what the customer is looking for. The product might be very good, but if it is positioned in the wrong way, it can be harmful.

Which other solutions did I evaluate?

I did not evaluate other options; this solution was the decision of the customer. However, in the past, I have evaluated and worked with Splunk and IBM.

What other advice do I have?

We use the public cloud deployment model.

I like the product, and I would recommend it, but I much prefer Splunk.

The beautiful thing about Fortinet is that they have integrated many, many solutions. Their platform is very powerful. In the case of the customer, if he decides to choose Fortinet, he'll largely be stuck with that one vendor. Fortinet does integrate with a few other vendors, but it's best if you use only their solutions. It's more efficient, you have more manageability and you get more value that way.

I would rate the solution seven out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
System Engineer / Network Consultant at a tech services company with 51-200 employees
Consultant
An affordable all-in-one solution that's very stable
Pros and Cons
  • "The solution is very stable. It's run for years without the need to do anything except, add new patches when they are available, which are always a good idea to install."
  • "They could work on their documentation. If there's anything about the solution that needs improvement, it's that. For example, documentation already is on a very high level but specifically on the CLI there are tons of features which can be fine-tuned and thousands of commands are very difficult to document. If they could make this easier, it would improve the overall solution."

What is most valuable?

The solution has an all-in-one approach. We buy one product and everything our customer needs is included. He doesn't have to pay any additional licenses to get more functionality, so everything is there and if we have to do any adjustments, it's also done very quickly and easily.

What needs improvement?

The solution can't be improved, but it can be managed more clearly. The solution just needs minor improvements. I'm quite sure Fortinet is already working on this.

They could work on their documentation. If there's anything about the solution that needs improvement, it's that. For example, documentation already is on a very high level but specifically on the CLI, there are tons of features which can be fine-tuned and thousands of commands are very difficult to document. If they could make this easier, it would improve the overall solution. 

For how long have I used the solution?

I've been using the solution for 1.5 years.

What do I think about the stability of the solution?

The solution is very stable. It has run for years without the need to do anything except, add new patches when they are available, which are always a good idea to install.

How was the initial setup?

The initial setup is quite easy.

What's my experience with pricing, setup cost, and licensing?

If we do an overall comparison with other products and also count additional licenses, which are necessary for other products, then the prices are comparative.

If we just leave it at base prices, for example, Splunk: Splunk is cheaper, but if you also count the price for licenses, reports, and other things - especially the megabytes and gigabytes of the lock data that you need - then it comes up to a much higher price than you have to pay for FortiSIEM which already includes these things in a base version.

What other advice do I have?

I would rate the solution nine out of ten. Our clients have been very happy with the solution.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner.
PeerSpot user
PeerSpot user
Manager, ICT Enterprise Services at a government with 201-500 employees
Real User
Has good business service summaries in the dashboards but it should have better integration abilities
Pros and Cons
  • "Analytics is the most valuable feature. The business service summaries in the dashboards and the correlations for the SIEM are also valuable features."
  • "Their product support, in general, is not that great. The product support is in the same ecosystem. Their support is improving but it's not that great.vvv"

What is our primary use case?

We use the on-prem deployment model of this solution. Our primary use case of this solution is for all of our infrastructure monitoring, applications, performance monitoring, and for security, incident, and event analysis. 

What is most valuable?

Analytics is the most valuable feature. The business service summaries in the dashboards and the correlations for the SIEM are also valuable features. 

What needs improvement?

Their product support, in general, is not that great. The product support is in the same ecosystem. Their support is improving but it's not that great.

It should also have better integration.

For how long have I used the solution?

I have been using FortiSIEM for four years.

What do I think about the stability of the solution?

It's a good product. It does what it is supposed to do. 

What do I think about the scalability of the solution?

Scalability required a lot of training. If the training isn't adequate you cannot enjoy the end results.

There are currently around ten users using this solution. They are mostly system and network administrators using this solution. We don't have plans to increase the usage. We are going to switch to another product. 

We require two staff members for the deployment and maintenance. 

How are customer service and technical support?

When you log a call, you don't get instant replies or if there is a bug they take ages to fix it and they ask you to hold.

Which solution did I use previously and why did I switch?

We didn't previously use another SIEM solution. 

How was the initial setup?

The installation is straightforward but the configuration is complex because it compromises of several aspects of the network infrastructure, servers, and the databases. You have to know what you want to gain out of this product. 

The deployment took around three months. There are a lot of dashboards to configure. It's not about just the installation. The planning phase and understanding what you want to get out of it, setting up the logs, and working on the correlations take time. 

What about the implementation team?

We used a local integrator for the deployment. They were good. When you consider the other SIEM products, this isn't a popular solution. When we implemented it, we were with the solution before it was acquired by Fortinet. It was a hassle. 

What's my experience with pricing, setup cost, and licensing?

Licensing is a one time cost. If you want to enable different modules then there will be additional costs. 

What other advice do I have?

Properly review this solution and your requirements. See how it will scale up to cloud requirements. Cloud technologies are becoming more prominent and you should see how you will be able to manage it with this tool.

It's a good product but you need to be well trained. If you don't have good training then you won't maximize the benefits of this product. 

I would rate it a seven out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer773925 - PeerSpot reviewer
ICT Architect at a insurance company with 51-200 employees
Real User
CMDB database collects data from a lot of pre-configured devices
Pros and Cons
  • "The most valuable feature is the dashboard. CMDB database collects data from a lot of pre-configured devices."
  • "The performance can be improved. Sometimes it takes a long time to fetch data."

What is our primary use case?

We use the on-prem model of this solution. Our primary use case is for malware and behavior monitoring. We also use it to monitor system performance and user behavior. 

What is most valuable?

The most valuable feature is the dashboard. CMDB database collects data from a lot of pre-configured devices. 

What needs improvement?

The performance can be improved. Sometimes it takes a long time to fetch data. 

For how long have I used the solution?

I have been using this solution for one and a half years.

What do I think about the stability of the solution?

It is very stable. 

What do I think about the scalability of the solution?

Scalability is very good. We currently have 150 users using this solution. We don't have plans to increase usage at the moment. 

What about the implementation team?

We implemented through Fortinet professional services. We were one of the first customers to implement the new version and it was a bit complex. I believe it has become easier. Deployment took them only a few hours. It didn't take a long time. 

What other advice do I have?

I would rate it an eight out of ten. They should implement better behavior monitoring features to make it a perfect ten. It should also have better integration with their own products. They have a lot of interfaces for other products but it's not so easy to integrate their own devices. 

I would recommend this solution to someone considering it. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Network and Security Administrator at PETRA Engineering Industries Co.
Real User
Hybrid Fortinet Fabric Solutions with a comprehensive view for all Fortinet products and a little support for other vendors
Pros and Cons
  • "The interface is very easy to use. The connector in the core has FortiSIEM support from the vendor."
  • "The nodes on our network did not comply with the SIEM solution. They use a different format parking log."

What is our primary use case?

We're using FortiSIEM as the main metadata server for all the security and infrastructure devices. We integrate a lot of nodes, switches, firewalls, and sandboxes with it to gain and covers performance, availability, change, and security monitoring aspects of network devices, servers, and applications.

How has it helped my organization?

FortiSIEM gives us a lot of valuable events and details by using a unified event-based framework to analyze all data including logs, performance monitoring data and provides a broad range of metrics.

What is most valuable?

The comprehensive view of the dashboard and the attribute base interface and the flexibility of implementation methods.

What needs improvement?

 The Fortinet Fabric should be more easy more friendly to use. They use a different parsing log format.

for example Symantec ATP is not supported by FortiSIEM. Our reseller provided us FortiSIEM as a service. They should also provide us with a dashboard to monitor and to deploy a correlations.

I think fortinet should improve the AI correlations by combining advanced statistical and heuristic analysis with behavioral whitelisting .

For how long have I used the solution?

I have been using the solution around six months.

What do I think about the stability of the solution?

Stability is the main feature we had looked for because of our environment, i.e. why we chose FortiSIEM. The stability is good. We just install a connector on the supervisor outside. 

With the stability of the connector, we faced some problems. The reseller asked us to reinstall the connector. The problem was with the reseller, not the connector.

How are customer service and technical support?

We used the solution's technical support for a lot of cases and tickets. Their responses are very good, kind, and quick. 

Which solution did I use previously and why did I switch?

They have a poor correlation. They didn't use any new concepts like Fortinet. They just display the logs as it is with no attribute base.

How was the initial setup?

The initial setup with Fortinet FortiSIEM Accelops was not easy. We had faced a few problems. but I think Fortinet should give more training courses for their resellers.

We needed to find what the weak points were.  in our network. Our deployment took up to two months. 

We were looking to deploy a unique correlation between nodes. We wanted to track the packets from our clouds Services like cloud sandbox and anti-spam to log our end-to-end connections.

The reseller told us that they comply with our solution. After that, we figured out that it was not going to very easy. FortiSIEM doesn't support ATP Symantec. 

They also did not support our web gateway log format.

What other advice do I have?

The interface is  easy to use but initial setup is not . The connector in the core has FortiSIEM support from the vendor. FortiSIEM supports a lot of vendors. It is a good product for us.

I rank it as eight on a scale from one to ten. because It doesn't support a lot of vendors and also the FortiSIEM still not common to use with fortinet partner maybe they doesn't give adequate training.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2025
Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros sharing their opinions.