it_user404421 - PeerSpot reviewer
Associate Director, Network Services at a university with 1,001-5,000 employees
Vendor
It can take logs from all my devices agentlessly and correlate data. I'd like to see a more streamlined dashboard.
Pros and Cons
  • "The primary valuable feature is that it has replaced a whole lot of other products with one platform."
  • "It lacks a "wizard" that shows a particular user's activity or particular circumstance. I think the interface is intimidating because there's so much information there."

How has it helped my organization?

Although we're still in training, we can expect to see and address issues in our network, such as configuration errors that caused latency between disc, storage and server that we weren't aware of before.

What is most valuable?

The primary valuable feature is that it has replaced a whole lot of other products with one platform. That's a huge win right there. It can take logs from all my devices agentlessly and correlate data. It already has a lot of the advanced analytics and dashboards that we need already built-in.

Accelops is also well positioned within the industry, for example, by partnering with Octave which we're using as a login index for Accelops. We're able to bring up a security operations center, which helps a lot of the newer information security people.

What needs improvement?

It lacks a "wizard" that shows a particular user's activity or particular circumstance. I think the interface is intimidating because there's so much information there. I'd like to see a better dashboard that pretty. I want to be able to see incidences or stats, depending on what I'm looking for to determine whether we're healthy, what's our security posture, SOX-incident problems. So streamlining all that information on the initial interface would be great.

What do I think about the stability of the solution?

So far, it appears to be stable. Early on, there were some lags with certain things happening and my guys weren't quite sure how stuff fit together, but I think that will wash out in the training. We need it to provide alerts, monitoring, security, and SIEM.

Buyer's Guide
Fortinet FortiSIEM
May 2024
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
771,170 professionals have used our research since 2012.

What do I think about the scalability of the solution?

We've had no issues with scalability.

How are customer service and support?

It's too early to comment on technical support. I don't have any complaints, and neither do my guys, so that's a good sign.

How was the initial setup?

They got the system up and running pretty easily and now he's working with the engineering groups and others to start making sure that the SM&NT logs are all set. Right now we're in ramp-up mode, so once it's fully loaded we'll be able to talk more about how it's performing with that volume of logs and all the dashboards and things that we started automating.

What about the implementation team?

I trust my server lead and his guys for the setup. They had to build a bigger box with new storage to keep all the new logs that we started pointing at it.

Which other solutions did I evaluate?

We knew we needed an SIEM tool, and actually looked at Accelops a year ago. At the time, it just wasn't stable enough and we didn't quite have the funding. Now, we did another review and Accelops came out on top with some improvements and better pricing. I found the initial money and had extra budget for ongoing maintenance.

What other advice do I have?

Any of the top SIEM tools like this is going to give you a lot of information and that in itself is the challenge. There's so much information that you need to have at least one person who's dedicated almost full-time to it.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user799953 - PeerSpot reviewer
it_user799953Network Security Engineer at Spectrotel
Real User

Presently on 4.10 version. You must deploy using Workers and Collectors. Or else the Supervisor take control of all the memory, Currently the Country location and IP does not match up. report as a Bug since v 4,2 version

it_user276174 - PeerSpot reviewer
Director of IT with 501-1,000 employees
Vendor
We've been able to monitor our account-hacking issues internally, including attempted attacks on our network and logins to accounts.

What is most valuable?

The security notifications and monitoring features.

How has it helped my organization?

With the online-based monitoring we've set up, we've been able to watch trends of attempted attacks on our network.

We're also able to monitor our account issues internally as attackers attempt to log into our accounts.

We fall under HIPAA so security is key.

What needs improvement?

As we're an SMB, I would like to see different licensing options and the solution is priced out of the reach of some small businesses. It was a priority for us, though, because of the HIPAA regulations we fall under, and a more attractive licensing structure would be nice for SMB's.

For the product itself, it's the configuration. You really have to have their help to configure the product. When hands are off and it's in maintenance mode, it's difficult to configure unless you're totally engrossed in the product on a day-to-day basis.

For how long have I used the solution?

I've used it for one year.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

9/10, based strictly on the limited experience with one person that I've had.

Technical Support:

9/10, based strictly on the limited experience with one person that I've had.

Which solution did I use previously and why did I switch?

We used freeware or third party apps (two or three of them), but we liked the consolidation of this product -- one interface, one screen -- to capture what the other applications were doing.

How was the initial setup?

It was complex because we didn't know the product. It's pretty in-depth, but once we got familiar with the software it made a lot of sense.

What about the implementation team?

We had the vendor help us implement, and they were 8/10.

What's my experience with pricing, setup cost, and licensing?

As mentioned above, they need to improve their licensing, but it depends on what industry segment they're going after. Maybe introduce some kind more attractive bundle for SMB's to help them get started with the product.

Which other solutions did I evaluate?

We did, but I don't recall which ones.

What other advice do I have?

Everyone's implementation will be different, so be very focused and deliberate in what you want to monitor, because you can inundate the system.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Fortinet FortiSIEM
May 2024
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
771,170 professionals have used our research since 2012.
Network Security Engineer at Technicom Mali
Real User
Top 5
A simple setup but needs better visibility and more correlation tools
Pros and Cons
  • "It is used as an alerting platform."
  • "The log collection and configuration management are not great."

What is our primary use case?

It is used as an alerting platform and has an availability manager.

What is most valuable?

We already have experience with Fortinet products, so dealing with Fortinet FortiSIEM is not complicated.

What needs improvement?

They should offer better visibility, more correlation tools and a better understanding of the network. Fortinet FortiSIEM already uses simple and standard protocols like SNMP, DuraMI and Syslog. Other solutions like QRadar use sFlow, so I think that they can do better.

In addition, the log collection and configuration management are not great.

For how long have I used the solution?

We have been using this solution for three years. We deployed Fortinet FortiSIEM at about three customer sites, and it is deployed on-premises.

What do I think about the stability of the solution?

The product is stable.

What do I think about the scalability of the solution?

It is a scalable solution.

How are customer service and support?

We have expertise with the product, so we don't use technical support often. We only require support for the error mark, and the support is quick and fast for that.

How was the initial setup?

The initial setup was simple, and we deployed Fortinet FortiSIEM in two days. We already had all the information regarding the customers' notes, and it was simple, quick and fast.

What's my experience with pricing, setup cost, and licensing?

It is cheaper than LogPoint or QRadar.

What other advice do I have?

I rate this solution a five out of ten. It is not as good as other solutions like QRadar, but it's cheaper than other products and very simple. In the next release, the visibility should consist of simple and standard protocols.

Regarding advice, if you don't have a dedicated team to handle your logs, don't have a big budget, and want a solution to correlate and collect logs from many vendors, Fortinet FortiSIEM is an excellent choice.

Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
PeerSpot user
Head - IT & SWIFT at a financial services firm with 1-10 employees
Real User
Top 20
Good dashboards and customization but issues with licensing
Pros and Cons
  • "FortiSIEM's best features are the dashboards and customization."
  • "An improvement would be if FortiSIEM's licensing was based on the number of nodes rather than the EPS."

What is our primary use case?

I use FortiSIEM for email events and security alarms.

What is most valuable?

FortiSIEM's best features are the dashboards and customization.

What needs improvement?

An improvement would be if FortiSIEM's licensing was based on the number of nodes rather than the EPS. In the next release, FortiSIEM should implement a central repository.

For how long have I used the solution?

I've been working with FortiSIEM for more than three years.

What do I think about the stability of the solution?

FortiSIEM's stability is quite good.

What do I think about the scalability of the solution?

FortiSIEM is scalable, though this is constrained by the licensing model.

How are customer service and support?

FortiSIEM's technical support is satisfactory, but its knowledge base could be better.

How would you rate customer service and support?

Positive

What about the implementation team?

We used an in-house team and the local vendor.

What's my experience with pricing, setup cost, and licensing?

FortiSIEM's licensing is based on EPS, and its pricing is competitive in the market.

Which other solutions did I evaluate?

I also evaluated LogRhythm and McAfee.

What other advice do I have?

I would give FortiSIEM a rating of seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
chief of cybersecurity at ECSSA El Salvador
Reseller
Allows us to combine SOC and NOC operations and has good reports, integrations, and support
Pros and Cons
  • "One of the most valuable features is that we can combine SOC and NOC operations in the same tool. We can provide NOC and SOC services in the same tool for two separate teams. There are plenty of third-party solutions that integrate with FortiSIEM. All these solutions already have a ready integration, and we have the possibility to create a custom connector for these solutions. Its reports are also very good."
  • "Its training can be improved. Its price also needs to be improved."

What is our primary use case?

We are an enterprise that resells services. We are like a small MSSP for Salvador and Central America region. We provide services to other enterprises.

Our clients have multiple use cases. Its most common use case to detect logging events from different IP addresses or locations. It is used to detect simultaneous logins by the same user from different IP addresses or locations, such as from different countries. It is also used to detect any attempts to log in to a server with root privilege and trying remote access with root privileges. 

How has it helped my organization?

With the help of FortiSIEM we have improved the cybersecurity posture of our clients and ours. Through the early detection of threats, it allows to follow up on each security incident. It is easy to communicate to asset managers about related security events, reducing remediation time.

What is most valuable?

One of the most valuable features is that we can combine SOC and NOC operations in the same tool. We can provide NOC and SOC services in the same tool for two separate teams.

There are plenty of third-party solutions that integrate with FortiSIEM. All these solutions already have a ready integration, and we have the possibility to create a custom connector for these solutions. Its reports are also very good.

What needs improvement?

Its training can be improved. Its price also needs to be improved.

For how long have I used the solution?

I have been using this solution for one year.

What do I think about the stability of the solution?

It has been good so far. We don't have any complaints about the tool.

What do I think about the scalability of the solution?

It is very scalable. It is easy to grow with this tool. We are going step-by-step, and we are doing good so far.

Our clients are big enterprises, such as banks, and we also have small businesses. In Salvador, as per a local compliance requirement, every business or enterprise needs to have a SIEM solution. We have an installation for 1,000 users.

How are customer service and technical support?

We are Fortinet's partner here in Salvador, and the tech support is really good. Their response time is also really good. We are very happy with this solution.

How was the initial setup?

The implementation process is kind of easy. We start in a small way. The challenge for us is the storage. We need to find a way to have storage redundancy so that if the main site fails, we have a copy of the data on a remote site. This is the challenge that we are facing right now.

What about the implementation team?

For its deployment and maintenance, we have a very small group of five people. We have a networking guy, a server guy, and a few analysts to maintain this platform.

What's my experience with pricing, setup cost, and licensing?

There is a licensing scheme for every case. There are three licensing schemes that we can choose from.

Which other solutions did I evaluate?

Our clients also evaluate other solutions such as Rapid7, McAfee, and LogRhythm. We have always been a Fortinet enterprise. We have people with Fortinet and other certifications in the industry, such as EasyConsole certifications. We can also support this solution for the Fortinet sites. That is the main differentiator between us and other vendors.

What other advice do I have?

I would advise others to start small and plan for future growth. 

I would rate Fortinet FortiSIEM an eight out of ten.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Security Manager at BKL
Real User
Seamless integration with FortiGate, and has an easy setup, but is lacking user behavior analytics
Pros and Cons
  • "The seamless integration with FortiGate is the solution's most valuable aspect."
  • "When compared with some competitors, in terms of performance, the CPU and RAM requirements and the capability of coordination with development all need some improvement."

What is our primary use case?

We primarily use the solution for integration with FortiGate Firewall. We use it for multiple authentification, malware detection, and protection from DDoS attacks.

What is most valuable?

The seamless integration with FortiGate is the solution's most valuable aspect.

What needs improvement?

When compared with some competitors, in terms of performance, the CPU and RAM requirements and the capability of coordination with development all need some improvement.

The solution should offer user behavior analytics in a future release.

For how long have I used the solution?

I've been using the solution for two years.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

We don't have any expansion requirements, so I've never looked into scalability.

How are customer service and technical support?

We've never reached out to technical support. If we need assistance, we typically look for FortiGate documents or scan their blog site. We handle any problems internally.

Which solution did I use previously and why did I switch?

We previously used an open-source solution called Elastic.

How was the initial setup?

The initial setup is easy.

What about the implementation team?

We received support from an integrator.

Which other solutions did I evaluate?

We evaluated AlienVault and SolarWinds. These were both within our limited budget, but we chose FortiSIEM because it integrated seamlessly with FortiGate firewall.

What other advice do I have?

We use the on-premises deployment model.

I'd recommend this solution to companies that have a FortiGate firewall and are on a limited budget. 

I'd rate the solution six out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user390012 - PeerSpot reviewer
Manager, Security Services at a financial services firm with 5,001-10,000 employees
Real User
We like the built-in reports and alerts, along with the extreme flexibility in reporting and rule generation.
Pros and Cons
  • "The most valuable features for us are the built-in reports and alerts, along with the extreme flexibility in reporting and rule generation."
  • "Creating parsers to try make unknown events or currently unsupported devices produce meaningful information is extremely cumbersome."

How has it helped my organization?

There are several examples, but the flexibility in reporting and alerting has given us the ability to have numerous teams be alerted for various security situations affecting each team's responsibilities.

What is most valuable?

The most valuable features for us are the built-in reports and alerts, along with the extreme flexibility in reporting and rule generation. The logs and search engine are also valuable features.

What needs improvement?

Creating parsers to try make unknown events or currently unsupported devices produce meaningful information is extremely cumbersome.

Additionally, lately there have been releases which have broken existing functions. This directly relates to support being an area that also needs improvement.

What do I think about the stability of the solution?

In general, the system is stable.

What do I think about the scalability of the solution?

We had to deploy several workers to keep up with event collection. This was one reason that the AO agent was developed and released -- to reduce the load on the managers and workers.

How are customer service and technical support?

Customer Service:

Customer service is mediocre, but the relationship is improving with focused attention on customers.

Technical Support:

Technical support is good.

Which solution did I use previously and why did I switch?

We were a a Cisco MARS customer and needed to replace the solution once Cisco ceased support.

How was the initial setup?

The initial setup is straightforward. There is a learning curve for the software, but overall it was up and running and collecting information in a matter of an hour post setup.

What about the implementation team?

We implemented it with out in-house team.

Which other solutions did I evaluate?

We didn't evaluate other options as this was a direct, suggested replacement to MARS.

What other advice do I have?

Watch the sizing requirements for the virtual machines and quantities needed to support the environment. Make sure you get sign-off from Accelops on proposed the configuration and load for what’s being planned on the deployment.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Termphong Tana - PeerSpot reviewer
Assistant to Vice President at IT Green Public Company Limited
Reseller
Plenty of features, good support, but lacking signature updates
Pros and Cons
  • "The most valuable features of Fortinet FortiSIEM are the SD-WAN, Global LAN, and application controls."
  • "Fortinet FortiSIEM could improve by having a signature update."

What is our primary use case?

We use Fortinet FortiSIEM for security, a gateway, and for authentication.

What is most valuable?

The most valuable features of Fortinet FortiSIEM are the SD-WAN, Global LAN, and application controls.

What needs improvement?

Fortinet FortiSIEM could improve by having a signature update.

For how long have I used the solution?

I have been using Fortinet FortiSIEM for approximately 16 years.

What do I think about the stability of the solution?

Fortinet FortiSIEM is stable. However, it was not stable from the beginning.

What do I think about the scalability of the solution?

Fortinet FortiSIEM is the best soltuions here in Thailand. There are many users and partners here.

There are 10 to 3,000 users in my company. Most of the users are specialists in IT. We plan to increase usage in the future.

How are customer service and support?

I have used the technical support and they have been good.

Which solution did I use previously and why did I switch?

I have used other solutions previously.

How was the initial setup?

The initial setup of Fortinet FortiSIEM was easy. The deployment would take a few days for the middle and large models.

We need some information for the customer, such as policies, before we can implement the solution.

What about the implementation team?

We do the implementation of Fortinet FortiSIEM. We use one IT specialist for the deployment and maintenance of the solution.

What other advice do I have?

I would advise others this solution is easy to use and has a lot of features. They should try it out.

I rate Fortinet FortiSIEM a seven out of ten

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2024
Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros sharing their opinions.