We performed a comparison between Fortinet FortiSIEM and Observer GigaStor based on real PeerSpot user reviews.
Find out in this report how the two Security Information and Event Management (SIEM) solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."Sentinel's most important feature is the ability to centralize all the logs in one place. There's no need to search multiple systems for information."
"We can use Sentinel's playbook to block threats. It covers all of the environment, giving us great visibility."
"Native integration with Microsoft security products or other Microsoft software is also crucial. For example, we can integrate Sentinel with Office 365 with one click. Other integrations aren't as easy. Sometimes, we have to do it manually."
"The solution has features that helped improve the security posture of our clients. It provides the ability to correlate a large variety of log sources very cost-effectively, especially for Microsoft sources."
"You can fine-tune the SOAR and you'll be charged only when your playbooks are triggered. That is the beauty of the solution because the SOAR is the costliest component in the market today... but with Sentinel it is upside-down: the SOAR is the lowest-hanging fruit. It's the least costly and it delivers more value to the customer."
"Mainly, this is a cloud-native product. So, there are zero concerns about managing the whole infrastructure on-premises."
"I've worked on most of the top SIEM solutions, and Sentinel has an edge in most areas. For example, it has built-in SOAR capabilities, allowing you to run playbooks automatically. Other vendors typically offer SOAR as a separate licensed solution or module, but you get it free with Sentinel. In-depth incident integration is available out of the box."
"Sentinel pricing is good"
"FortiSIEM provides a single PIN to monitor SOC and NOC. It's a nice tool for integration and monitoring. It provides multiple categories for monitoring based on security designations like low, medium, and high."
"FortiSIEM's log correlation is good."
"The product's initial setup phase was easy."
"To add workers and even collectors is pretty easy."
"The solution is easy to use and user-friendly."
"I like FortiSIEM because it integrates natively with our other Fortinet solutions and the Fortinet Fabric, but it also integrates with Cisco, Palo Alto and other security fabrics."
"This solution offers extensive customization options, making it possible to adapt it precisely to their requirements."
"Easy alert setup which enables different alerts in different categories."
"This solution allows us to see exactly what is going on in the network and we can very quickly solve issues with users."
"It can help to write your rules, organize firewalls, your block, and also your protocols and IP address to come in or out of your network."
"I also have the ability to see an application's performance, to see what's going on, why a network is slow, why this program for this user is experiencing a delay or some network issue"
"It's able to capture packets and, after a long time, you can come and use that information; to check, to analyze - everything you would want to do. So it's very good and helpful if you want to protect your data. It is stored in a certain place where you can access it every time you want to analyze it."
"There are many valuable features, but understanding end-user response times stands out. It provides a score-based evaluation of user experience, helping customers quickly pinpoint whether issues originate from the network, server, client, or application. Additionally, it facilitates in-depth analysis of application dependencies."
"The ability to capture packets. It is not only for monitoring. That is very important for a company that wants to keep an eye on the packets, the transactions, the flows..."
"Sometimes, it is hard for us to estimate the costs of Microsoft Sentinel."
"If you're looking to use canned queries, the interface could be a little more straightforward. It's not immediately intuitive regarding how you use it. You have to take a canned query and paste it into an operational box and then you hit a button... They could improve the ease of deploying these queries."
"I can't think of anything other than just getting the name out there. I think a lot of customers don't fully understand the full capabilities of Azure Sentinel yet. It is kind of like when they're first starting to use Azure, it might not be something they first think about. So, they should just kind of get to the point where it is more widely used."
"It would be good to have some connectors for third-party SIEM solutions. Many customers are struggling with the integration of Azure Sentinel with their on-premise SIEM. Microsoft is changing the log structure many times a year, which can corrupt a custom integration. It would be good to have some connectors developed by Microsoft or supply vendors, but they are not providing such functionality or tools."
"When it comes to ingesting Azure native log sources, some of the log sources are specific to the subscription, and it is not always very clear."
"Currently, the watchlist feature is being utilized, and although there have been improvements, it is still not fully optimized."
"The AI capabilities must be improved."
"For certain vendors, some of the data that Microsoft Sentinel captures is redacted due to privacy reasons."
"Our customers are noticing configuration available in the GUI interface and I think that they should be equal."
"Fortinet FortiSIEM could improve to extend to several locations or sites."
"The process of installing Fortinet FortiSIEM and the customization of the alerts take too long."
"There is no proper guide for integration or configuration."
"Fortinet FortiSIEM is a little out of sight and needs more marketing efforts to be popular in the market."
"The performance can be improved. Sometimes it takes a long time to fetch data."
"There could be more AI features included in the product."
"The policy editing should be easier. Right now, it's too hard."
"I would like to have more than 4TB of storage available in the portable version of this solution."
"Graphics need improvement. Because a lot of the information there you have to input first in some case to have full potential. It could be more automated."
"Maybe the graphical user interface could be simplified to allow people to use it more easily. It's already good, but they can work more on it to make it even easier."
"GigaStor feeds into Apex. So, the area where there could be improvement would be in artificial intelligence. For example, the incorporation of more advanced machine learning or AI capabilities could enhance its functionality."
Fortinet FortiSIEM is ranked 8th in Security Information and Event Management (SIEM) with 63 reviews while Observer GigaStor is ranked 91st in Network Monitoring Software with 7 reviews. Fortinet FortiSIEM is rated 7.6, while Observer GigaStor is rated 9.0. The top reviewer of Fortinet FortiSIEM writes "It's cheaper than other solutions with the same features but lacks integration with many third-party vendors". On the other hand, the top reviewer of Observer GigaStor writes "Aids significantly in the threat-hunting process and provides a score-based evaluation of user experience". Fortinet FortiSIEM is most compared with IBM Security QRadar, Splunk Enterprise Security, LogRhythm SIEM, Wazuh and ThousandEyes, whereas Observer GigaStor is most compared with Gigamon Deep Observability Pipeline, Wireshark, Kentik and Cisco Nexus Dashboard Data Broker. See our Fortinet FortiSIEM vs. Observer GigaStor report.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.