We performed a comparison between Fortinet FortiSIEM and Fortra's Intermapper based on real PeerSpot user reviews.
Find out in this report how the two Security Information and Event Management (SIEM) solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."You can fine-tune the SOAR and you'll be charged only when your playbooks are triggered. That is the beauty of the solution because the SOAR is the costliest component in the market today... but with Sentinel it is upside-down: the SOAR is the lowest-hanging fruit. It's the least costly and it delivers more value to the customer."
"One of the most valuable features of Microsoft Sentinel is that it's cloud-based."
"Sentinel enables us to ingest data from our entire ecosystem. In addition to integrating our Cisco ASA Firewall logs, we get our Palo Alto proxy logs and some on-premises data coming from our hardware devices... That is very important and is one way Sentinel is playing a wider role in our environment."
"What is most useful, is that it has a good connection to the Microsoft ecosystem, and I think that's the key part."
"Sentinel is a SIEM and SOAR tool, so its automation is the best feature; we can reduce human interaction, freeing up our human resources."
"The solution has features that helped improve the security posture of our clients. It provides the ability to correlate a large variety of log sources very cost-effectively, especially for Microsoft sources."
"I've worked on most of the top SIEM solutions, and Sentinel has an edge in most areas. For example, it has built-in SOAR capabilities, allowing you to run playbooks automatically. Other vendors typically offer SOAR as a separate licensed solution or module, but you get it free with Sentinel. In-depth incident integration is available out of the box."
"The scalability is great. You can put unlimited logs in, as long as you can pay for it. There are commitment tiers, up to six terabytes per day, which is nowhere close to what any one of our customers is running."
"The product is quite well-organized. The GUI makes it easy to navigate."
"Our customer did not have security monitoring in the first place. With this solution, it provided security posture management and visibility about the security landscape and threats that they had."
"The most valuable feature is the dashboard. CMDB database collects data from a lot of pre-configured devices."
"Technical support is helpful."
"The solution is very stable. It's run for years without the need to do anything except, add new patches when they are available, which are always a good idea to install."
"Analytics is the most valuable feature. The business service summaries in the dashboards and the correlations for the SIEM are also valuable features."
"We find the solution to be stable."
"The advanced agents used to collect logs have been most valuable. We have also made use of the advanced intelligence this solution offers."
"It's a nice graphical interface, a nice map, that relates Layer 1 to Layer 3, virtually instantly, to the Helpdesk support staff. It provides a default place to get critical information so we can deploy our staff."
"It's all today portal-based which is a good feature for us."
"What is really cool about HelpSystems InterMapper is that because of its SNMP base, you can integrate all different makes and models on the same map. You, of course, can have more than one map, but you have an option to have visibility into the entire network from one centralized system. You can monitor IPs, routers, radios, DC power plants, and UPS. You can do it all from one network management and monitoring solution. That's what really makes HelpSystems Intermapper great. Another great thing about HelpSystems InterMapper is that you can really bundle different probes under one device. You can have a bundled device. You can monitor the physical status of a host based on the IP availability. You can also monitor services and actually see if anything happens. You can quickly determine whether it is the application layer, host layer, or network layer. HelpSystems Intermapper gives such a unique representation of a network. Ever since we started using HelpSystems InterMapper, we don't have to document everything in a detailed format and store it somewhere. Right now, it is really a combination of network topology, network monitoring, and network analyzing. So, in my opinion, it is awesome. When you have your SNMP topology defined, you don't require a dedicated NMS engineer to manage your system, which is another great thing about HelpSystems InterMapper. I see how our operators get so excited by having the ability to map a device or interface and connect interfaces together. HelpSystems InterMapper is also very operator friendly; not just user friendly, but also operator friendly. This is a unique feature, and it works really great."
"The most valuable features are its: log history, real-time monitoring capabilities, accuracy - the number of false positives is very low, and the mapping features."
"I would like to be able to monitor applications outside of the Azure Cloud."
"The playbook is a bit difficult and could be improved."
"Everyone has their favorites. There is always room for improvement, and everybody will say, "I wish you could do this for me or that for me." It is a personal thing based on how you use the tool. I do not necessarily have those thoughts, and they are probably not really valuable because they are unique to the context of the user, but broadly, where it can continue to improve is by adding more connectors to more systems."
"Sentinel should be improved with more connectors. At the moment, it only covers a few vendors. If I remember correctly, only 100 products are supported natively in Sentinel, although you can connect them with syslog. But Microsoft should increase the number of native connectors to get logs into Sentinel."
"They can work on the EDR side of things... Every time we need to onboard these kinds of machines into the EDR, we need to do it with the help of Intune, to sync up the devices, and do the configuration. I'm looking for something on the EDR side that will reduce this kind of work."
"Only one thing is missing: NDR is not available out-of-the-box. The competitive cloud-native SIEM providers have the NDR component. Currently, Sentinel needs NDR to be powered from either Corelight or some other NDR provider."
"It could have a better API to be able to automate many things more extensively and get more extensive data and more expensive deployment possibilities. It can gain some points on the automation part and the integration part. The API is very limited, and I would like to see it extended a bit more."
"Sometimes, we are observing large ingestion delays. We expect logs within 5 minutes, but it takes about 10 to 15 minutes."
"Fortinet FortiSIEM is a little out of sight and needs more marketing efforts to be popular in the market."
"It would be good if the solution offered even more configuration options, especially in relation to the VPN so that it continues to be a very flexible option."
"There could be more AI features included in the product."
"The log collection and configuration management are not great."
"The biggest thing that could be better is a quicker response to support cases."
"Fortinet FortiSIEM could improve by having a signature update."
"They need to integrate better with Cisco and Palo Alto."
"Patching is not great - we're not getting the support we'd expect."
"It's a smaller solution so tools are not as advanced as you would find in a larger solution"
"They can do a better job with SLA reporting. It does some basic reporting, but it really doesn't offer the ability to monitor devices by groups, customers, or carrier to give an overall health performance of specifically-defined environments. That's where HelpSystems Intermapper could have done a better job. I would love to see advanced SLA monitoring and reporting in this solution. They already have a lot of ingredients. They already have SNMP polling. It is really about what people are looking for from SLA monitoring, especially someone who looks at the network topology. You want to see your endpoints. You want to see half of your endpoints by simply analyzing ICMP or SNMP-based availability of your endpoints. Having an ability to define your group and how you bring devices into your group would be a huge benefit."
"I'd love to see more of the network management side of it coming back into it. If we were able to run scripts to bounce ports on switches, that would be great. It's asking a lot, but it's actually very doable because I do it through scripting into other products. If we could incorporate that directly into Intermapper, that would be fantastic."
Earn 20 points
Fortinet FortiSIEM is ranked 8th in Security Information and Event Management (SIEM) with 63 reviews while Fortra's Intermapper is ranked 77th in Network Monitoring Software. Fortinet FortiSIEM is rated 7.6, while Fortra's Intermapper is rated 8.2. The top reviewer of Fortinet FortiSIEM writes "It's cheaper than other solutions with the same features but lacks integration with many third-party vendors". On the other hand, the top reviewer of Fortra's Intermapper writes "It tremendously cuts down our troubleshooting timeframe, but needs advanced SLA monitoring and reporting". Fortinet FortiSIEM is most compared with IBM Security QRadar, Splunk Enterprise Security, LogRhythm SIEM, Wazuh and ThousandEyes, whereas Fortra's Intermapper is most compared with Zabbix. See our Fortinet FortiSIEM vs. Fortra's Intermapper report.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.