The primary thing I use it for is monitoring IPS because we have 12 or 14 Cisco IPS devices, and the Cisco solution for monitoring that many IPS devices is hokey at best, aside from it being expensive. I also use it when we’re trying to track down activity on a particular IP address – I use the query engine to search for things like that.
Senior Network Security Architect at a retailer with 1,001-5,000 employees
It helps us identify the origin of a DoS attack, where it came from, how long it lasted, how intense it was, etc. and take the appropriate action.
Pros and Cons
- "The primary thing I use it for is monitoring IPS because we have 12 or 14 Cisco IPS devices, and the Cisco solution for monitoring that many IPS devices is hokey at best, aside from it being expensive."
- "One of the things that actually opened a ticket about (and they couldn’t help me) is when traffic is leaving our network, it’ll only report the source."
What is most valuable?
How has it helped my organization?
We’ve had some situations where we’ve either gotten hit with a DOS attack or we’ve gotten notification that we’ve been blacklisted because some IP that belongs to us is roaming the internet trying to bogusly log in to SNMP servers. So, we’ll take that IP, or wherever the DoS is coming from, and run a query over the last 30 days or so, to see just what the activity on that machine has been, and make various decisions from that. In a couple of cases it’s meant to shut down the machines and get them off the network because they’ve obviously got some kind of malware on them. In other cases, it’s been a matter of determining the exact scope of DoS – where it came from, how long it lasted, how intense it was, etc.
What needs improvement?
One of the things that actually opened a ticket about (and they couldn’t help me) is when traffic is leaving our network, it’ll only report the source. I would think that if it’s examining the packets that it should also be able to give me the destination. It’s not possible to tell me whether it reached the destination, but it would be helpful to know where it was headed when it left the network. That field is always empty in the query.
For how long have I used the solution?
I've used it for about a year.
Buyer's Guide
Fortinet FortiSIEM
September 2026
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,262 professionals have used our research since 2012.
What was my experience with deployment of the solution?
No serious issues.The biggest issue I had with their deployment methodology as a virtual appliance – with the way things our VM farms are structured – there are only a couple of people that are allowed to bring up OVAs, which is the way they ship the product, so I have to get their time to do any kind of upgrade.That’s why I recently queried the helpdesk on what was required to do the upgrade that’s available to us (at no cost), and they pointed me to a manual which I haven’t had time to download yet. My guess is I’m going to have to deploy a separate OVA.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
We've not had any issues so far.
How are customer service and support?
Customer Service:
The only complaint I have is that they wouldn’t issue a license until they had the check in their hands, which is not my experience with other vendors. If you issue a PO for something, usually you get a license immediately – in their case they wouldn’t until they had actually gotten payment, which was a little frustrating.
Technical Support:I have tried to open some tickets, and usually they’ll respond with a note at the top of the response. It says “if you’re responding to this email do it above this line,” and I didn’t see that the first time I got an email like that, so for weeks they kept sending me emails saying I hadn’t responded to their initial contact. To me that was a little bit nit-picky.
Which solution did I use previously and why did I switch?
I inherited a solution that was discontinued by the vendor, and I was charged with finding a replacement.
How was the initial setup?
Once we got the OVA file, and I was able to commandeer some time from the appropriate people here, it wasn’t an issue.
What about the implementation team?
It was in-house. Part of the initial purchase included some on-site time with one of their engineers, so I used that time to do an upgrade while he was here.
What's my experience with pricing, setup cost, and licensing?
The pricing seems fairly standard in terms of the pricing model, so how it compares to other similar products I don’t know. The people I took this to about replacing the other product didn’t seem to blink at the price.
Which other solutions did I evaluate?
We ran a PoC for Accelops for a trial period, so we didn’t look as much into other products.
What other advice do I have?
It would be to get as good an estimate as you can of what EPS's you’ll need before you get pricing and so forth. We underestimated what we would need, which is what precipitated ordering additional licensing and not being able to get them right that.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Systems Administrator with 501-1,000 employees
Dashboards provide us with the real-time status of our network, including specific alerts and granular monitoring.
Pros and Cons
- "It gives greater visibility via the dashboards into the real-time status of the network and also provides specific alerts and performance monitoring."
- "Issues that could have been resolved in 30-60 minutes sometimes took months, but they have improved."
Valuable Features
The granular monitoring capabilities. Also, it's very configurable.
Improvements to My Organization
It gives greater visibility via the dashboards into the real-time status of the network. Additionally, it also provides specific alerts and performance monitoring.
Room for Improvement
Some of the out-of-box dashboards could be more useful, as they’re not configured out-of-box. Some other products we’ve used give a lot more information right out of the box. With Accelops, we didn’t get quite enough useful information at the beginning. Ping monitors (STMs) are highly configurable, but it would be nice to have a simpler monitor to go with it, like a simple ping monitor. As it is, we have to go through three different processes and 30 minutes to get the ping monitor up with email notifications. It should have an easier way to configure some of these more common monitors.
Use of Solution
I've used it for two years, but the firm has had the solution in place for longer.
Stability Issues
The product is always stable, but there were a few bugs. During some of the upgrades, fixing one problem revealed another, so we had to go through several patch iterations to find a bug-free version that works for us.
Scalability Issues
None. Far more scalable than is required for us.
Customer Service and Technical Support
Customer Service:
Great - we’d give it a 10/10.
Technical Support:6/10 - as far as the techs go, they are knowledgeable, but when trying to get a hold of a tech or have them call back, they weren’t responsive. It was one of my biggest frustrations with the product, and I started to look elsewhere for another solution at one point. Issues that could have been resolved in 30-60 minutes sometimes took months, but they have improved.
Other Advice
Just do your research – the product does a lot, but it may be more than you’re looking for. Also, be aware that it requires a lot of time to maintain, set up, and configure.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Fortinet FortiSIEM
September 2026
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,262 professionals have used our research since 2012.
Director of IT with 501-1,000 employees
We've been able to monitor our account-hacking issues internally, including attempted attacks on our network and logins to accounts.
Pros and Cons
- "With the online-based monitoring we've set up, we've been able to watch trends of attempted attacks on our network, and we're also able to monitor our account issues internally as attackers attempt to log into our accounts."
- "As we're an SMB, I would like to see different licensing options and the solution is priced out of the reach of some small businesses."
What is most valuable?
The security notifications and monitoring features.
How has it helped my organization?
With the online-based monitoring we've set up, we've been able to watch trends of attempted attacks on our network.
We're also able to monitor our account issues internally as attackers attempt to log into our accounts.
We fall under HIPAA so security is key.
What needs improvement?
As we're an SMB, I would like to see different licensing options and the solution is priced out of the reach of some small businesses. It was a priority for us, though, because of the HIPAA regulations we fall under, and a more attractive licensing structure would be nice for SMB's.
For the product itself, it's the configuration. You really have to have their help to configure the product. When hands are off and it's in maintenance mode, it's difficult to configure unless you're totally engrossed in the product on a day-to-day basis.
For how long have I used the solution?
I've used it for one year.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
9/10, based strictly on the limited experience with one person that I've had.
Technical Support:9/10, based strictly on the limited experience with one person that I've had.
Which solution did I use previously and why did I switch?
We used freeware or third party apps (two or three of them), but we liked the consolidation of this product -- one interface, one screen -- to capture what the other applications were doing.
How was the initial setup?
It was complex because we didn't know the product. It's pretty in-depth, but once we got familiar with the software it made a lot of sense.
What about the implementation team?
We had the vendor help us implement, and they were 8/10.
What's my experience with pricing, setup cost, and licensing?
As mentioned above, they need to improve their licensing, but it depends on what industry segment they're going after. Maybe introduce some kind more attractive bundle for SMB's to help them get started with the product.
Which other solutions did I evaluate?
We did, but I don't recall which ones.
What other advice do I have?
Everyone's implementation will be different, so be very focused and deliberate in what you want to monitor, because you can inundate the system.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
ICT Architect at a insurance company with 51-200 employees
Never crashes but lacks integration with Fortinet products
Pros and Cons
- "The most valuable feature is the anomaly-reporting alarms."
- "This is a very stable product - we have never had a crash with it."
- "Areas for improvement would be the ease of use and the integration with Fortinet's own products."
What is most valuable?
The most valuable feature is the anomaly-reporting alarms.
What needs improvement?
Areas for improvement would be the ease of use and the integration with Fortinet's own products.
For how long have I used the solution?
I've been using this solution for three years.
What do I think about the stability of the solution?
This is a very stable product - we have never had a crash with it. It does use a lot of resources, but this doesn't affect its performance.
What do I think about the scalability of the solution?
The scalability is ok and is improved by using Elasticsearch.
How are customer service and support?
The technical support has improved a lot and is now ok.
How was the initial setup?
The initial setup was a little difficult because no good guidelines were available. However, this has since been improved. It took around six months to finish a complete deployment.
What's my experience with pricing, setup cost, and licensing?
I have a five-year contract for this product, with no additional costs.
What other advice do I have?
I would give this solution a rating of seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber Security Analyst at a tech services company with 11-50 employees
Provides valuable CIM-based predefined rules and an efficient automated response feature
Pros and Cons
- "Its automated response feature has benefited our customer communication. Analysts feel more confident in providing timely responses."
- "There could be more AI features included in the product."
What is our primary use case?
We use the product for threat detection.
What needs improvement?
There could be more AI features included in the product.
For how long have I used the solution?
We have been using Fortinet FortiSIEM for more than two years.
What do I think about the stability of the solution?
I rate the platform's stability an eight and a half out of ten.
How are customer service and support?
The technical support services need improvement.
How would you rate customer service and support?
Positive
What other advice do I have?
They have released a new update recently. With the help of AVPN, users can log in from another country directly using CIM-based predefined rules. Its automated response feature has benefited our customer communication. Analysts feel more confident in providing timely responses.
I recommend other users to go with Fortinet FortiSIEM and rate the product an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Popular Comparisons
Splunk Enterprise Security
SentinelOne Singularity Cloud Security
SentinelOne Singularity Endpoint
Dynatrace
IBM Security QRadar
Microsoft Sentinel
Elastic Security
LogRhythm SIEM
Rapid7 InsightIDR
Cortex XSIAM
Gigamon Deep Observability Pipeline
Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?
- What Questions Should I Ask Before Buying SIEM?
- What are the pros and cons of internal SOC vs SOC-as-a-Service?














