We performed a comparison between Fortinet FortiSIEM and Icinga based on real PeerSpot user reviews.
Find out in this report how the two Security Information and Event Management (SIEM) solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."I like the KQL query. It simplifies getting data from the table and seeing the logs. All you need to know are the table names. It's quite easy to build use cases by using KQL."
"You can fine-tune the SOAR and you'll be charged only when your playbooks are triggered. That is the beauty of the solution because the SOAR is the costliest component in the market today... but with Sentinel it is upside-down: the SOAR is the lowest-hanging fruit. It's the least costly and it delivers more value to the customer."
"It is able to connect to an ever-growing number of platforms and systems within the Microsoft ecosystem, such as Azure Active Directory and Microsoft 365 or Office 365, as well as to external services and systems that can be brought in and managed. We can manage on-premises infrastructure. We can manage not just the things that are running in Azure in the public cloud, but through Azure Arc and the hybrid capabilities, we can monitor on-premises servers and endpoints. We can monitor VMware infrastructure, for instance, running as part of a hybrid environment."
"In Azure Sentinel, we have found, they do have a store in their capability. AI and intelligence features. We found that to be very helpful for us because some other things we do need to integrate again or find another vendor for the store"
"There are some very powerful features to Sentinel, such as the integration of various connectors. We have a lot of departments that use both IaaS and SaaS services, including M365 as well as Azure services. The ability to leverage connectors into these environments allows for large-scale data injection."
"It has a lot of great features."
"The most valuable features in my experience are the UEBA, LDAP, the threat scheduler, and integration with third-party straight perform like the MISP."
"The part that was very unexpected was Sentinel's ability to integrate with Azure Lighthouse, which, as a managed services solution provider, gives us the ability to also manage our customers' Sentinel environments or Sentinel workspaces. It is a big plus for us. With its integration with Lighthouse, we get the ability to monitor multiple workspaces from one portal. A lot of the Microsoft Sentinel workbooks already integrate with that capability, and we save countless amounts of money by simply being able to almost immediately realize multitenant capabilities. That alone is a big plus for us."
"Technical support is helpful."
"The interface is very easy to use. The connector in the core has FortiSIEM support from the vendor."
"We find the solution to be stable."
"FortiSIEM helped us discover all the threats at the time that were attacking the IT services of the company. We now have multiple-level authentication."
"There are things like dashboards and reports (pre-configured and custom) that let me know that things are operating the way they should be, and when they are not."
"Easy alert setup which enables different alerts in different categories."
"The most valuable feature of Fortinet FortiSIEM is the correlation of many events."
"I like FortiSIEM because it integrates natively with our other Fortinet solutions and the Fortinet Fabric, but it also integrates with Cisco, Palo Alto and other security fabrics."
"The value of Icinga is that it has hundreds of plugins, so it's really easy to monitor pretty much anything."
"The drafts are easy but what I like about Icinga is that there are many add-ons that you can download."
"An affordable solution for small organizations to do basic network monitoring."
"I like the ability to amend and adjust things really easily, which is useful in a case where you could make it auto-discover and then set a template to say all of these applications or servers under this template have an automatic threshold set that you’d set up manually."
"Macros and the ability to connect it to Google Maps are valuable features."
"Icinga has multiple automation and integration features. There is an API for everything and a web UI for configurations. The APIs enable you to automate tasks in Icinga. We can also use plugins to talk to the API. The Icinga Director talks to a database in the background, and you can import settings from the CMDB to all systems in Icinga."
"Icinga does the job and is fairly stable."
"The apply rules feature saves a lot of time."
"I would like to be able to monitor applications outside of the Azure Cloud."
"The playbook development environment is not as rich as it should be. There are multiple occasions when we face problems while creating the playbook."
"The performance could be improved. If I create 15 to 20 lines for a single-use case in KQL, sometimes it takes more time to execute. If I create use cases within a certain timeline, the result will show in .01 seconds. A complex query takes more time to get results."
"Its documentation is not so simple. It is easy for somebody who is Microsoft certified or more closely attached to Microsoft solutions. It is not easy for those who are working on open-source platforms. There isn't a central point where everything is documented, and there is no specific training or certification."
"The following would be a challenge for any product in the market, but we have some in-house apps in our environment... our apps were built with different parameters and the APIs for them are not present in Sentinel. We are working with Microsoft to build those custom APIs that we require. That is currently in progress."
"The troubleshooting has room for improvement."
"If Azure Sentinel had the ability to ingest Azure services from different tenants into another tenant that was hosting Azure Sentinel, and not lose any metadata, that would be a huge benefit to a lot of companies."
"For certain vendors, some of the data that Microsoft Sentinel captures is redacted due to privacy reasons."
"They should enhance the solution's AI capabilities, including XDR and EDR."
"The backup and recovery process for this solution needs improvement."
"I would like to see easier implementation in the future."
"Not very good on non-API features, lacks that functionality."
"Its training can be improved. Its price also needs to be improved."
"Areas for improvement would be the ease of use and the integration with Fortinet's own products."
"We expect the latest patch from Fortinet FortiSIEM to give the ability to work with signature files."
"Fortinet FortiSIEM could improve by having better integration and extensions. This would benefit by allowing us to give more rules."
"Icinga’s automation could be improved."
"The solution lacks many features important to higher-level IT management and network support."
"It needs Trap SNMP. I saw the documentation for Zabbix, that it has its own built-in product which handles SNMP traps, and there's nothing similar in Icinga or Nagios. I think this feature is most important for me."
"I think the software is quite good, but we have had problems with getting it to recognize certain areas and amend certain checks, where we needed so we would have to create backend scripts for those checks. Though, being open source, it has the support to create backend scripts, it would be better to have these scripts in-built."
"One of the areas that are frustrating is remote monitoring for more than one machine."
"One thing that Icinga lacks is the capability to create advanced and customized dashboards within the tool itself."
"In general, the product does not look good. However, it does what it is supposed to do. So, the improvements should focus on usability and UI."
"We have found some problems with Nagios, and support isn't very responsive."
Fortinet FortiSIEM is ranked 8th in Security Information and Event Management (SIEM) with 63 reviews while Icinga is ranked 22nd in Network Monitoring Software with 16 reviews. Fortinet FortiSIEM is rated 7.6, while Icinga is rated 7.6. The top reviewer of Fortinet FortiSIEM writes "It's cheaper than other solutions with the same features but lacks integration with many third-party vendors". On the other hand, the top reviewer of Icinga writes "A stable, scalable and cost-effective solution that helps with inbuilt scripts for easy modification". Fortinet FortiSIEM is most compared with IBM Security QRadar, Splunk Enterprise Security, LogRhythm SIEM, Wazuh and ThousandEyes, whereas Icinga is most compared with Zabbix, Checkmk, Nagios Core, Nagios XI and Centreon. See our Fortinet FortiSIEM vs. Icinga report.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.