Try our new research platform with insights from 80,000+ expert users
reviewer773925 - PeerSpot reviewer
ICT Architect at a insurance company with 51-200 employees
Real User
Aug 14, 2019
CMDB database collects data from a lot of pre-configured devices
Pros and Cons
  • "The most valuable feature is the dashboard. CMDB database collects data from a lot of pre-configured devices."
  • "The performance can be improved. Sometimes it takes a long time to fetch data."

What is our primary use case?

We use the on-prem model of this solution. Our primary use case is for malware and behavior monitoring. We also use it to monitor system performance and user behavior. 

What is most valuable?

The most valuable feature is the dashboard. CMDB database collects data from a lot of pre-configured devices. 

What needs improvement?

The performance can be improved. Sometimes it takes a long time to fetch data. 

For how long have I used the solution?

I have been using this solution for one and a half years.
Buyer's Guide
Fortinet FortiSIEM
January 2026
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.

What do I think about the stability of the solution?

It is very stable. 

What do I think about the scalability of the solution?

Scalability is very good. We currently have 150 users using this solution. We don't have plans to increase usage at the moment. 

What about the implementation team?

We implemented through Fortinet professional services. We were one of the first customers to implement the new version and it was a bit complex. I believe it has become easier. Deployment took them only a few hours. It didn't take a long time. 

What other advice do I have?

I would rate it an eight out of ten. They should implement better behavior monitoring features to make it a perfect ten. It should also have better integration with their own products. They have a lot of interfaces for other products but it's not so easy to integrate their own devices. 

I would recommend this solution to someone considering it. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Network and Security Administrator at a engineering company with 1,001-5,000 employees
Real User
Jul 7, 2019
Hybrid Fortinet Fabric Solutions with a comprehensive view for all Fortinet products and a little support for other vendors
Pros and Cons
  • "The interface is very easy to use. The connector in the core has FortiSIEM support from the vendor."
  • "The nodes on our network did not comply with the SIEM solution. They use a different format parking log."

What is our primary use case?

We're using FortiSIEM as the main metadata server for all the security and infrastructure devices. We integrate a lot of nodes, switches, firewalls, and sandboxes with it to gain and covers performance, availability, change, and security monitoring aspects of network devices, servers, and applications.

How has it helped my organization?

FortiSIEM gives us a lot of valuable events and details by using a unified event-based framework to analyze all data including logs, performance monitoring data and provides a broad range of metrics.

What is most valuable?

The comprehensive view of the dashboard and the attribute base interface and the flexibility of implementation methods.

What needs improvement?

 The Fortinet Fabric should be more easy more friendly to use. They use a different parsing log format.

for example Symantec ATP is not supported by FortiSIEM. Our reseller provided us FortiSIEM as a service. They should also provide us with a dashboard to monitor and to deploy a correlations.

I think fortinet should improve the AI correlations by combining advanced statistical and heuristic analysis with behavioral whitelisting .

For how long have I used the solution?

I have been using the solution around six months.

What do I think about the stability of the solution?

Stability is the main feature we had looked for because of our environment, i.e. why we chose FortiSIEM. The stability is good. We just install a connector on the supervisor outside. 

With the stability of the connector, we faced some problems. The reseller asked us to reinstall the connector. The problem was with the reseller, not the connector.

How are customer service and technical support?

We used the solution's technical support for a lot of cases and tickets. Their responses are very good, kind, and quick. 

Which solution did I use previously and why did I switch?

They have a poor correlation. They didn't use any new concepts like Fortinet. They just display the logs as it is with no attribute base.

How was the initial setup?

The initial setup with Fortinet FortiSIEM Accelops was not easy. We had faced a few problems. but I think Fortinet should give more training courses for their resellers.

We needed to find what the weak points were.  in our network. Our deployment took up to two months. 

We were looking to deploy a unique correlation between nodes. We wanted to track the packets from our clouds Services like cloud sandbox and anti-spam to log our end-to-end connections.

The reseller told us that they comply with our solution. After that, we figured out that it was not going to very easy. FortiSIEM doesn't support ATP Symantec. 

They also did not support our web gateway log format.

What other advice do I have?

The interface is  easy to use but initial setup is not . The connector in the core has FortiSIEM support from the vendor. FortiSIEM supports a lot of vendors. It is a good product for us.

I rank it as eight on a scale from one to ten. because It doesn't support a lot of vendors and also the FortiSIEM still not common to use with fortinet partner maybe they doesn't give adequate training.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Fortinet FortiSIEM
January 2026
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
it_user799953 - PeerSpot reviewer
Network Security Engineer at a comms service provider with 51-200 employees
Real User
Jun 15, 2019
Correlates incidents between products and notifies our SOC accordingly
Pros and Cons
  • "It gives us the opportunity to generate notifications based upon rules that get triggered, and the rules could be specific to PCI, HIPAA, GIBA, NIST, and so forth."
  • "The backup and recovery process for this solution needs improvement."

What is our primary use case?

We are a partner, and we use this solution to ingest our customers' syslogs data for their firewalls.

How has it helped my organization?

This solution allows us to ingest syslogs from Fortinet firewalls and other products into what we call FortiSIEM. This is a processor that correlates it with the event types and incidents. It gives us the opportunity to generate notifications based upon rules that get triggered, and the rules could be specific to PCI, HIPAA, GIBA, NIST, and so forth. All of these incidents are now correlated and sent up to a dashboard or emailed, where, as a SOC, we can review these incidents and triage the necessary resolution.

What needs improvement?

The backup and recovery process for this solution needs improvement.

I would like to see a database with more structure in terms of maintenance and ease of use. The process of creating is much simpler than that of duplication. The procedures are not proper for handling its PostgreSQL database.

For how long have I used the solution?

More than two years.

What do I think about the stability of the solution?

I would say that this solution is stable when it is configured and deployed by the Fortinet professional team.

What do I think about the scalability of the solution?

The scalability is there, and you can expand on the EPS (Events Per Second) as needed.

We do plan on selling this service to our customers that can see the benefit in it. We will probably introduce an incident response application to help triage incidents at a faster level.

How are customer service and technical support?

Technical support is very good. The people in support are excellent, and they know this product in and out. They are very quick to respond and the resolution is very quick.

How was the initial setup?

The initial setup for this solution is straightforward, although we are not yet in full production. During the past two years, while we have been implementing, we have found a lot of bugs in the software. As such, we're still not in a state where we can go into full production. For example, if you are certified for PCI then one of the standards is that you have to have proper backup recovery in place. This solution is lapsing in that area. 

Two staff are required for deployment and maintenance.

What about the implementation team?

We used Fortinet consultants for the deployment.

What's my experience with pricing, setup cost, and licensing?

We bought the perpetual license, so we own the product, but there is a three-year support renewal fee for that.

Which other solutions did I evaluate?

We did evaluate Splunk before choosing this solution, but it was too much on the high end for our business model.

What other advice do I have?

We are very impressed with this product. However, they have to fix their backup and recovery procedure and provide a good DR service without charging for a secondary license.

I would rate this solution a seven and a half out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner.
PeerSpot user
Secteamlead67 - PeerSpot reviewer
Security Team Leader at a tech services company with 11-50 employees
Reseller
Mar 20, 2019
Our customers have seen improvement in their connection with load balancing on both connections
Pros and Cons
  • "Some of our customers who use this solution have seen improvement in their connection with load balancing on both connections."
  • "Our customers are noticing configuration available in the GUI interface and I think that they should be equal."

What is our primary use case?

We are a system integrator and we resell this solution.

How has it helped my organization?

Some of our customers who use this solution have seen improvement in their connection with load balancing on both connections.  

What needs improvement?

Our customers are noticing configuration available in the GUI interface and I think that they should be equal.

What do I think about the stability of the solution?

Stability and scalability are perfect. 

How was the initial setup?

The initial setup wasn't complex. It took three days to deploy and we required two people for the deployment. 

What other advice do I have?

I would rate it a nine out of ten. The configuration should be equal with the GUI interface. 

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller.
PeerSpot user
Technical Lead at Arcon Labs at a tech services company with 51-200 employees
Real User
Apr 29, 2018
It's complicated to deploy but detection rules are flexible
Pros and Cons
  • "AccelOps can handle a lot of data and it's just so important to true monitoring. Also, I can create a lot of rules to detect anything I like."
  • "Does not have load-sharing or high-availability, and these are important things to implement. I can do the same things in another way, but not naturally having these features makes it complicated."

What is our primary use case?

My primary use case is that it is an analyst tool for hunting on your site network.

How has it helped my organization?

The platform is nice. It is not easy to implement, but once you do so, there is a lot of value from the platform. 

What is most valuable?

AccelOps can handle a lot of data and it's just so important to true monitoring. That is the strong point of AccelOps.

The second one is detecting. I can create a lot of rules to detect anything I like, and this is another strong point.

It's also the only SIEM platform on the market that has health monitoring capabilities, and correlates. For example, if a service is going down I can detect that it is going down and correlate it. For example, if it's because of an exploit can correlate this. It's a nice feature.

What do I think about the stability of the solution?

I think all SIEM platforms have a problem handling a lot of data. My response is "it depends." Depends on the people, depends on the product, depends on the technology. To implement any technology you need good people, and this is independent of the label of the company or technology. The stability is not bad, it's not good. It's a complicated question.

What do I think about the scalability of the solution?

I don't have any feature for load-sharing or high-availability, and these are important things to implement. I can do the same things in another way, but not naturally having these features makes it complicated. For example, the design is bad because you have one supervisor on one machine and you handle everything off this machine supervisor. It is a design problem. The technology also has limitations because you have a lot of memory and a lot of processors, but you have a limit with processors and memory, which causes problems with scalability. 

How are customer service and technical support?

It's equal to any technical support. You need to go to level one, level two, level three to reach their engineers. It is complicated. With any technology it is like this. But my level of skill here is high, and going to level one, level two, level three is complicated. You have a ladder to solve the problems quickly. That's the problem. Any platform, any vendor has the same problem. You need to go through levels until you find one guy who can solve your problem.

Which solution did I use previously and why did I switch?

I used a solution previously. I switched because I needed evolving technology. I needed to evolve to smart features.

The most important criteria when selecting a vendor is price. After that it's detection.

How was the initial setup?

For the first steps you have some help. At the beginning you have priority support, you have engineers. After that you pay.

It's complex because you need to evaluate a lot of things.

What other advice do I have?

I advise that you should plan your financial resources and plan the platform. Also, be sure to test the performance ability, as well as scalability. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user675411 - PeerSpot reviewer
Senior Technical Consultant at a integrator with 201-500 employees
Vendor
Aug 20, 2017
Configuration in initial setup is complex. Product's analytics provide log info letting you see threats.
Pros and Cons
  • "Analytics. It can provide log information from the device. With log information, I can see if there is a threat"
  • "If there is a configuration on the wrong side of the network or there are changes that result in harm to our IT infrastructure, the solution should immediately fix it."

How has it helped my organization?

From CMDB configuration monitoring, it can provide information changes.

What is most valuable?

Analytics. It can provide log information from the device. With log information, I can see if there is a threat

What needs improvement?

In the CMDB configuration monitoring. Example, if there is a configuration on the wrong side of the network or there are changes that result in harm to our IT infrastructure, the solution should immediately fix it.

What do I think about the stability of the solution?

Yes.

What do I think about the scalability of the solution?

Yes.

How are customer service and technical support?

Very good.

Which solution did I use previously and why did I switch?

FortiSIEM is better than previous products.

How was the initial setup?

Complex due to the configuration.

What's my experience with pricing, setup cost, and licensing?

Please be cheaper and more simplified.

Which other solutions did I evaluate?

Yes, but I cannot mention it because of privacy issues.

What other advice do I have?

Please do a PoC.

Disclosure: My company has a business relationship with this vendor other than being a customer. I'm Partner.
PeerSpot user
PeerSpot user
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Real User
Jun 22, 2017
The product is a well rounded performer when it comes to combined Infrastructure and Security monitoring, however in traditional SIEM bake-offs, they need a lot more flavour to make it exciting.

Introduction: 

How many of you remember Cisco MARS? Well, if you don’t, let me remind you that they were one of the earliest SIEM products around that stemmed from the infrastructure monitoring space. MARS was geared more towards monitoring and reviewing network infrastructure including their utilization, performance availability and logs. After a brief run in enterprises that were Cisco heavy, the product died a natural death. People who were involved in the product left Cisco and started AccelOps (Accelerate Operations). As a product, they took the fundamentals of data collection and integrated infrastructure log, event monitoring to the data analytics platform. The result is a promising product called AccelOps.

They have since been acquired by Fortinet, marking their foray into the larger Enterprise SIEM market dominated by the likes of HP, IBM, Splunk, etc.

AccelOps:

As you can guess, by virtue of collecting data from various sources like network devices and servers, AccelOps is a product that provides fully integrated SIEM, file integrity monitoring (FIM), configuration management database (CMDB), and availability and performance monitoring (APM) capabilities in a single platform.

  • APM Capability: This is their strong suit and it is MARS on steroids. AccelOps excels in capturing statistics to provide insights into system health. This provides value in a MSSP/NOC/SOC setup as there is no need for an additional monitoring platform. Again, Syslog or SNMP are your best bets for APM.
  • File Integrity Monitoring: Very few SIEM products (think AlienVault) offer native FIM capabilities and to see it in AccelOps is refreshing. The way they do so is no surprise as FIM can only be done effectively using an agent-based approach and Accelops does the same.
  • CMDB: AccelOps has the capability to keep track of all the elements in an organisation’s network infrastructure like network devices, UPS, servers, storage, hyper-visors, and applications. Using the data, a Centralised Management Database (CMDB) is available in AccelOps. This again is very unique and even AlienVault with all its Unified SIEM branding, does not shine as much as AccelOps does.
  • SIEM: Now that all the data from various network infrastructure is available in AccelOps along with CMDB, the ability to cross-correlate, in real-time, becomes easy and AccelOps does that using its own patented correlation engine. The SIEM capability comes with all the bells and whistles one would expect – rules, dashboards, alerting, analytics, intelligence, etc.

Now let us look at the Strengths and Weakness of AccelOps as a product

The Good:

  • AccelOps’ combination of SIEM, FIM and APM capabilities in a single box helps in Centralised operations as well as security monitoring.
  • AccelOps serves as a centralised data aggregation platform for system health data, network flow data, as well as event log data.
  • AccelOps has a mature integration capability with traditional incident management and workflow tools like ServiceNow, ConnectWise, LanDesk and RemedyForce.
  • From a deployment flexibility point of view, AccelOps excels in virtualisation environments. However, they are also available in traditional form factors. If customers prefer cloud, they are also available for deployments in either public, private or hybrid clouds.
  • From an architecture perspective, they have three layered tiers.
    1. The Collector tier does exactly what the name suggests – collects data from end log sources.
    2. The Analytics tier receives data from the collector tier. This analytics tier is built on big data architecture fundamentals supporting a master/slave setup. In AccelOps terms, it is a Supervisor/Worker setup.
    3. The Storage tier then serves as the data sink housing the CMDB and the big data file system.
  • Because of the architecture setup, the scalability is not an issue with AccelOps. It does scale well with clustering at Analytics and Storage tiers.

The Not So Good:

  • The most obvious is that AccelOps as a product has relatively low visibility in the market. However, this is bound to change with the Fortinet buy. They will hopefully be seen in more competitive bids and evaluations.
  • While AccelOps tries to be a “Jack of All”, it unfortunately is a master of none. This means that the product has poor support for some third-party security technologies, such as data loss prevention (DLP), application security testing, network forensics and deep packet inspection (DPI).  This hinders the product's versatility in large environments.
  • Parsing is a key aspect of SIEM and in this area too AccelOps lacks extensive coverage as seen amongst competition. While most of the popular ones are parsed out of the box, others require custom parser development skills, which unfortunately requires a steep learning curve or product support to help build.
  • While for Network engineers and analysts the interface makes sense, from a SIEM view, the usability could definitely be improved. This issue is evident when looking at dashboards, report engines, alerts, etc., which seem to be afflicted with information overdose.
  • Ease of deployment is there, however, the configuration takes a lot of time considering the fact that there are several tool integrations to be done before it can generate value. Some of the configurations are really complex and may lead to the user or admin being spooked. We were reminded of the MARS days time and again while evaluating this product.
  • The UI, while presenting data in a very informative way, suffers from too much clutter, hindering usability. While this is a personal opinion, with SIEM tools comparisons against the likes of IBM, Splunk, and even LogRhythm, the AccelOps UI does not excite. We hope that Fortinet brings to the fore its UI maturity to AccelOps, thereby becoming much more savvy.
  • Correlation capabilities are very good when it comes to data visibility, compliance, and infrastructure monitoring use cases. However, when it comes to threat-hunting, trend analysis, behaviour profiling, AccelOps has a lot of ground to cover.
  • Without Infrastructure data, AccelOps loses its edge. As a traditional SIEM, collecting only Event logs makes it look like a pretty basic SIEM. This can be quite an issue in organisations where infrastructure monitoring is already being done by other tools. Unless customers duplicate data sets across  the tools, the value is poor.

Conclusion:

All in all, the product is a well rounded performer when it comes to combined infrastructure and security monitoring, however in traditional SIEM bake-offs, they need a lot more flavour to make it exciting. Hopefully the Fortinet buy will do just that. We will continue to watch out for this product and its road map in coming months.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user701958 - PeerSpot reviewer
it_user701958Consulting System Engineer at a tech company with 1,001-5,000 employees
Real User

This looks like a review from another site which not a real customer review.

PeerSpot user
Network Engineer at a sports company with 51-200 employees
Real User
May 25, 2017
I can write my own parsers for the devices that are not supported. I am unable to perform complex/nested queries.
Pros and Cons
  • "The ability to write my own parsers for the devices that are not supported by Fortinet is the most valuable feature."
  • "The reporting feature is not very attractive for the upper management and I am not able to perform complex/nested queries."

How has it helped my organization?

It is provides extremely fast and flexible query of logs/events on the network. For example, it’s easy to write a quick query for all the “authentication” requests on the network, regardless of where they came from, i.e., during the past days, weeks or months.

What is most valuable?

The ability to write my own parsers for the devices that are not supported by Fortinet is the most valuable feature. It’s impossible to find an application that supports every device/manufacturer that we have. Thus, being able to write my own parsers for device logs, allows for greater scalability.

What needs improvement?

The reporting feature is not very attractive for the upper management and I am not able to perform complex/nested queries. However, it does function well for our day-to-day operations.

What do I think about the stability of the solution?

We did experience some stability issues. The parser engine crashes often, but it does recover without any noticeable impact to the performance or service.

What do I think about the scalability of the solution?

There were no scalability issues; the product scales well for us.

How is customer service and technical support?

Support was very good when owned by AccelOps. I have not opened any recent cases with Fortinet since its buyout.

How was the initial setup?

The setup was pretty complex, but we had great support from AccelOps.

What's my experience with pricing, setup cost, and licensing?

I haven’t looked at the latest offerings or licensing models since Fortinet bought this product. Previously, AccelOps was looking to add other Tableau reporting modules for more complex reporting purposes. This was not attractive to us, due to the high cost of Tableau's licensing. Also, it required licensing for an event forwarding engine to be installed on the servers. The cost was getting high when we looked at licensing for 50-plus servers.

Which other solutions did I evaluate?

We only evaluated this solution and loved the capabilities that it offers. We decided to take a chance and I’m not sorry that we did. Overall, the experience has been very positive.

What other advice do I have?

Make sure you size the solution to the number of devices and servers on the network. Don’t be afraid to add additional workers.

Try to avoid using WMA formats for log retrieval of the busy servers; this is extremely resource-intensive. Price out the event forwarding engine that they offer and add it to your budget.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2026
Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros sharing their opinions.