Fortinet FortiSIEM Room for Improvement

HamedWasel - PeerSpot reviewer
Senior Network Security Engineer at Orange

FortiSIEM needs to expand its integration with third-party vendors. I don't know if Forcepoint has been added, but there were limited resources for integrating Forcepoint solutions when we implemented FortiSIEM. It integrates well with other Fortinet products and solutions from established cybersecurity companies like Palo Alto but doesn't integrate with some of the newer vendors. 

I would also like to see FortiSIEM add more of the features available in FortiSOAR. You need to buy two separate solutions to get these features, but they should all be available in one product. 

View full review »
Babar Shahbaz - PeerSpot reviewer
Head of Product Management (Cloud & Digital) at Pakistan Telecommunication Company Limited

FortiSIEM is not a market leader in the SIEM space. In SIEM solutions, typically, our customers ask for Splunk, or they ask for Logarithm. Some legacy customers ask for IBM. This isn’t as popular. Fortinet needs to grow in that perspective. They need to become a leader in the magic quadrant of Gartner and be seen as visionary so that the top customers, the big customers, take them seriously in the SIEM space.

View full review »
SrikanthS - PeerSpot reviewer
Senior Manager - Technical at Sify Technologies

When our team tried configuring logs for Microsoft SQL, it did not work.

The next release should improve database monitoring. Compared to servers and security devices, working with database and log configuration is not easy.

View full review »
Buyer's Guide
Fortinet FortiSIEM
April 2024
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
767,847 professionals have used our research since 2012.
Ali Mohamed - PeerSpot reviewer
Account Manager at Cairo International Airport Co.

FortiSIEM could be better integrated with other vendors. 

View full review »
VA
CISO at a financial services firm with 501-1,000 employees

Network detection and response is a separate product. That's how I ended up with Wazuh. I'm looking for something to help me on the network and endpoint level. The vendor must look to consolidate and improve that area.

View full review »
ZaidoonAbuhanak - PeerSpot reviewer
SALES PRODUCT MANAGER at NOURNET

There are some connectivity issues with FortiAnalyzer and FortiGate.

They need to integrate better with Cisco and Palo Alto. 

View full review »
CO
Senior Network Associate at AMCON, Inc.

Sometimes, if there are changes made by a user on a database server, it can be difficult to get that information on the fly. I would like to see a situation where once I specify a user with the database server I need, and with the changes they have performed on that, I don't need to continue my search pattern to drill down just to get the information.

When you're generating a report on the report line, sometimes it is very important to understand the criteria for creating the database to get the report you want. If FortiSIEM can improve on that, the user is looking for specific information, and it comes by. You don't need a technical person to generate a report. It's a bit difficult for you to generate it without drilling down. You need to keep clicking, and narrowing down your search to get what you want. 

If there will be some level of info, I like the reporting on FortiAnalyzer because one can see the number of people consuming bandwidth on the network, who the top users are, at the critical button you specified, and how long the duration is. FortiSIEM is not as easy.

View full review »
SrikanthS - PeerSpot reviewer
Senior Manager - Technical at Sify Technologies

Our team tried configuring MS SQL database logs with Fortinet FortiSIEM, but it did not work for some time.

Fortinet FortiSIEM's database monitoring could be made easier, like the servers and the security devices.

View full review »
RE
Director, Infrastructure and Operations at a comms service provider with 11-50 employees

Their technical support is horrible. By horrible, I mean a train wreck of a disaster that has fallen off a bridge and caught fire.

The out-of-the-box log ingestion for the supported devices is fine. The main issues arise when you're trying to ingest a log source that's not supported. You're left to figure it out yourself. You have to figure out the custom parsing yourself. There should be better support for nonstandard log sources. That's because unless you can ingest logs from all of your key controls, the solution will have gaps. Out of the box, this product doesn't support a lot of normal security devices that are common, and then you get into building custom parsers yourself to get it to work.

The other problem is infrastructure stability. The architecture scaling rules that the vendor provides are vastly understated. So, we constantly run into stability problems that we end up figuring out and solving by throwing more infrastructure at it because they're understating the infrastructure requirements. It is understandable that they would do that, and you see why they would do that, but it is causing no end of problems.

View full review »
Alain ClovisBapfunya - PeerSpot reviewer
Cyber Security Specialist at EAST-NB

The only drawback is the licensing model. It can get expensive if you want to integrate more solutions.

View full review »
Ijeoma Nkemjika - PeerSpot reviewer
Customer Success Manager at Digitank Technology

The solution's interface could be modernized and improved.

View full review »
SI
Principal Cloud Architect at Viria Security Oy

This solution is not very good on non-API features and lacks that functionality. We've raised multiple tickets to Fortinet about this and they are pending there. The product development hasn't been fast enough to ensure it can function on the cloud. It's excellent when you download and get the security locks but in areas like Microsoft 365, you have to fetch the security access using APIs and they don't update quickly enough. If Microsoft announces a new service today, we have to wait at least six months before FortiSIEM start supporting it. It's crucial that the API support is updated, for now FortiSIEM lacks functionality compared to its competitors.

View full review »
Niranjan Singh - PeerSpot reviewer
Principal Solution Architect- Security & Privacy at Sify Technologies

Fortinet FortiSIEM is a little out of sight and needs more marketing efforts to be popular in the market.

View full review »
Kumar Vaibhav - PeerSpot reviewer
Solutions Architect at In2IT Technologies

The UI could improve in Fortinet FortiSIEM. Humans view the UI frequently for data and if it was more visually pleasing it would be beneficial.

View full review »
TamimKhan - PeerSpot reviewer
Solution Architect at Tiger IT Bangladesh Limited

They should enhance the solution's AI capabilities, including XDR and EDR.

View full review »
DM
Soc analyst at Konvergenz

At times, I have noticed that Fortinet FortiSIEM suddenly goes down, and because of this, I have to reboot the servers from the engineers. Usually, I have to restart the panel again to get the product functioning. The aforementioned area of concern has been around for a very long time, making it something where improvements are required.

The stability of the product is an area of concern where improvements are required.

ArcSight can provide a detailed report for a year in a PDF format. In Fortinet FortiSIEM, there is a need to put in manual effort to get a detailed report. In Fortinet FortiSIEM, if I get reports for a specific time frame, I have to manually narrow them down by myself, after which I will not be able to get them in a Word or PDF format, which can be challenging.

View full review »
Stefan Bächer - PeerSpot reviewer
IT Security & CyberSecurity Consultant at digitalDefense Information Systems GmbH

Customer support service could be better.

View full review »
AK
Asst Programmer Data Center at a consultancy with 10,001+ employees

We have recently faced many issues in terms of support and their turnaround time for giving support as well as their patch level. The patching is one of the significant issues we face with Fortinet SIEM. We're at the enterprise level and we're not getting the support we'd expect. They really need to bring in new features like proper dashboards and alert systems and a real-time alert system which would be beneficial for users.

View full review »
HO
Research Associate at a comms service provider with 1,001-5,000 employees

Fortinet FortiSIEM should consider converting the purchase model from a CapEX investment into a pay-per-use model. By doing this, it will be more attractive for more customers.

The product does not have Security Orchestration and Automation Response, I would recommend adding this feature.

View full review »
AK
Asst Programmer Data Center at a consultancy with 10,001+ employees

We expect the latest patch from Fortinet FortiSIEM to give the ability to work with signature files.

The patch management on the software needs to be better. We have not received frequent updates from their site. That's the major challenge for us. Going by the latest trends there are lots of cyber attacks happening in the entire world. All of the latest trends, patches, file updates, and hash updates should be released as soon as possible, whilst an attack is detected the patch has to be released on time.

View full review »
Abdul-MuminIddrisu - PeerSpot reviewer
CCO at oduma solutions ltd

The interface needs some improvements because it's a bit cumbersome when you're trying to view items. It takes some time to get used to. Additionally, sometimes the scrolling does not work.

View full review »
SM
Network Security Engineer at Go Faster

This is a great product for everyone. The disadvantage is the product portfolio.

We need more incidents automatically to protect our network.

We need to see incident reports about the event log, without events from the administrator or through human interaction.

In the next release, I would like to have automated generation reports of incident reports.

View full review »
RN
Cyber Security Analyst at a retailer with 1,001-5,000 employees

With FortiSIEM, the issue has to do with the ways we can generate a report. It's not as flexible compared to that with other SIEM tools, like Splunk.

When you work with a service provider who is using FortiSIEM as a service for other clients, you cannot run more than 30 clients on one tool. You cannot onboard, which would consume more resources and would make it slower. Also, resource consumption would be high.

View full review »
RO
Infrastructure Operations Manager at a computer software company with 501-1,000 employees

The biggest thing that could be better is a quicker response to support cases.

View full review »
MC
Presales IT at a tech services company with 201-500 employees

The process of installing Fortinet FortiSIEM and the customization of the alerts take too long. You need to customize the alerts that come to the dashboard so that not everything is an alert. If everything is an alert, nothing is an alert. This is a complicated process and takes time.

In future releases, I would like to see a resource for common environments like VMware and VMware/FortiGate or VMware/Check Point. The resource should discover and speed up implementation.

View full review »
SY
Senior Product Manager at a financial services firm with 201-500 employees

Fortinet FortiSIEM could improve to extend to several locations or sites.

View full review »
it_user404364 - PeerSpot reviewer
Information Security Officer at a aerospace/defense firm with 10,001+ employees

The dashboards need to be improved. It gives you so much detail, but sometimes too much detail, especially to an executive, it's too much. I need to be able to understand what my situational awareness is by looking at a simple graph. I've already made a specific feature request to just make it look sexier because that's what customers like to see.

View full review »
it_user799953 - PeerSpot reviewer
Network Security Engineer at Spectrotel

The backup and recovery process for this solution needs improvement.

I would like to see a database with more structure in terms of maintenance and ease of use. The process of creating is much simpler than that of duplication. The procedures are not proper for handling its PostgreSQL database.

View full review »
it_user404421 - PeerSpot reviewer
Associate Director, Network Services at a university with 1,001-5,000 employees

It lacks a "wizard" that shows a particular user's activity or particular circumstance. I think the interface is intimidating because there's so much information there. I'd like to see a better dashboard that pretty. I want to be able to see incidences or stats, depending on what I'm looking for to determine whether we're healthy, what's our security posture, SOX-incident problems. So streamlining all that information on the initial interface would be great.

View full review »
it_user276174 - PeerSpot reviewer
Director of IT with 501-1,000 employees

As we're an SMB, I would like to see different licensing options and the solution is priced out of the reach of some small businesses. It was a priority for us, though, because of the HIPAA regulations we fall under, and a more attractive licensing structure would be nice for SMB's.

For the product itself, it's the configuration. You really have to have their help to configure the product. When hands are off and it's in maintenance mode, it's difficult to configure unless you're totally engrossed in the product on a day-to-day basis.

View full review »
DD
Network Security Engineer at Technicom Mali

They should offer better visibility, more correlation tools and a better understanding of the network. Fortinet FortiSIEM already uses simple and standard protocols like SNMP, DuraMI and Syslog. Other solutions like QRadar use sFlow, so I think that they can do better.

In addition, the log collection and configuration management are not great.

View full review »
SC
Head - IT & SWIFT at a financial services firm with 1-10 employees

An improvement would be if FortiSIEM's licensing was based on the number of nodes rather than the EPS. In the next release, FortiSIEM should implement a central repository.

View full review »
MB
chief of cybersecurity at ECSSA El Salvador

Its training can be improved. Its price also needs to be improved.

View full review »
TA
Security Manager at BKL

When compared with some competitors, in terms of performance, the CPU and RAM requirements and the capability of coordination with development all need some improvement.

The solution should offer user behavior analytics in a future release.

View full review »
it_user390012 - PeerSpot reviewer
Manager, Security Services at a financial services firm with 5,001-10,000 employees

Creating parsers to try make unknown events or currently unsupported devices produce meaningful information is extremely cumbersome.

Additionally, lately there have been releases which have broken existing functions. This directly relates to support being an area that also needs improvement.

View full review »
Termphong Tana - PeerSpot reviewer
Assistant to Vice President at IT Green Public Company Limited

Fortinet FortiSIEM could improve by having a signature update.

View full review »
it_user293910 - PeerSpot reviewer
Senior Enterprise Information Security Architect at a healthcare company with 1,001-5,000 employees

The way that upgrades are handled could be a bit cleaner. That might have been improved in the new version, but where we are, the upgrade process takes the system down for the period of the upgrade. So the lost data during that downtime can be frustrating.

View full review »
AK
Asst Programmer Data Center at a consultancy with 10,001+ employees

The solution needs to be form flow diagram automatically with AWS platform

View full review »
IS
Security Analyst at netfiniti

The solution is almost 100% perfect. It's already quite simple and easy to configure. In that sense, no improvements are needed.

You do seem to be constantly learning new things with the product. There's a bit of an ongoing learning curve in terms of usage. Right now, I'm learning about higher availability and that's an ongoing process.

It would be good if the solution offered even more configuration options, especially in relation to the VPN so that it continues to be a very flexible option. 

The solution offers both command line and GUI visualizations. They need to ensure that their GUI offers just as much flexibility on the configuration as the command line structure.

View full review »
SC
Partner at a security firm with 11-50 employees

The initial setup is complex. They need to make it easier in terms of implementation. That said, all CM implementations are quite difficult. It may not be a fault of this particular product.

The policy editing should be easier. Right now, it's too hard. 

Some of the parts of the mapping tool should be in the product itself. It would make our efforts easier.

The product is quite expensive. It's something clients always comment on.

View full review »
AH
Solutions Consultant at a comms service provider with 51-200 employees

The support of the product changed recently, and I don't think it's for the better. They should work to improve the support they offer to clients.

They also have to improve their import perfection solution.

View full review »
AK
Manager, ICT Enterprise Services at a government with 201-500 employees

Their product support, in general, is not that great. The product support is in the same ecosystem. Their support is improving but it's not that great.

It should also have better integration.

View full review »
SJ
Senior Security Engineer at a tech services company with 1,001-5,000 employees

It's difficult to integrate unsupported devices with FortiSIEM compared to QRadar. It's easier to integrate and develop processes in QRadar. It's harder to develop a custom process in FortiSIEM. 

View full review »
PD
Assistant Engineer at Harel Mallac Technologies Ltd

Fortinet FortiSIEM could improve by having better integration and extensions. This would benefit by allowing us to give more rules.

View full review »
HW
System Engineer / Network Consultant at a tech services company with 51-200 employees

The solution can't be improved, but it can be managed more clearly. The solution just needs minor improvements. I'm quite sure Fortinet is already working on this.

They could work on their documentation. If there's anything about the solution that needs improvement, it's that. For example, documentation already is on a very high level but specifically on the CLI, there are tons of features which can be fine-tuned and thousands of commands are very difficult to document. If they could make this easier, it would improve the overall solution. 

View full review »
MK
Technical manager at a tech services company with 11-50 employees

I would like to see more integration with other platforms.

View full review »
NW
Chief Technical Officer at a computer software company with 51-200 employees

I would like to see easier implementation in the future.

View full review »
JG
IT Executive: Operations & Security at Icon Information Systems (Pty) Ltd

When they started out after acquiring AccelOps, the user interface wasn't that great. But from version 5.0 they have obviously radically changed the interface, aligning it to the rest of the Forti products from a user experience point of view. This means that there is constant improvement on the interface side of the solution. The other thing that I've noticed is when searching for very old incidents, there is a slight delay. It obviously has to pull that information from the backend database, and the key point to note is that it depends on how you set it up in the backend where factors such as disk types and disk array configs come into play.

View full review »
it_user277014 - PeerSpot reviewer
Systems Administrator with 501-1,000 employees

Some of the out-of-box dashboards could be more useful, as they’re not configured out-of-box. Some other products we’ve used give a lot more information right out of the box. With Accelops, we didn’t get quite enough useful information at the beginning. Ping monitors (STMs) are highly configurable, but it would be nice to have a simpler monitor to go with it, like a simple ping monitor. As it is, we have to go through three different processes and 30 minutes to get the ping monitor up with email notifications. It should have an easier way to configure some of these more common monitors.

View full review »
IO
Cyber Security Analyst at a tech services company with 11-50 employees

There could be more AI features included in the product.

View full review »
HH
Cybersecurity Engineer at a tech services company with 11-50 employees

The graphs on the user interface could be improved as we often experience glitches. 

View full review »
it_user275922 - PeerSpot reviewer
Network Engineer at a sports company with 51-200 employees

The reporting feature is not very attractive for the upper management and I am not able to perform complex/nested queries. However, it does function well for our day-to-day operations.

View full review »
RP
Security Engineer L1 at a media company with 11-50 employees

There is no proper guide for integration or configuration. They need to improve the documentation library.

View full review »
it_user284157 - PeerSpot reviewer
Senior Network Security Architect at a retailer with 1,001-5,000 employees

One of the things that actually opened a ticket about (and they couldn’t help me) is when traffic is leaving our network, it’ll only report the source. I would think that if it’s examining the packets that it should also be able to give me the destination. It’s not possible to tell me whether it reached the destination, but it would be helpful to know where it was headed when it left the network. That field is always empty in the query.

View full review »
it_user1020687 - PeerSpot reviewer
Network and Security Administrator at PETRA Engineering Industries Co.

 The Fortinet Fabric should be more easy more friendly to use. They use a different parsing log format.

for example Symantec ATP is not supported by FortiSIEM. Our reseller provided us FortiSIEM as a service. They should also provide us with a dashboard to monitor and to deploy a correlations.

I think fortinet should improve the AI correlations by combining advanced statistical and heuristic analysis with behavioral whitelisting .

View full review »
it_user293913 - PeerSpot reviewer
IT Security and Compliance Officer at a energy/utilities company with 501-1,000 employees

Ease-of-use for end users that do not spend every day in the product.

Also, the presentation of historical and trending data in dashboards needs to be improved immensely. Something as simple as an RRDtool graphing mechanism on a dashboard would be a huge improvement to the product.

View full review »
it_user675411 - PeerSpot reviewer
Senior Technical Consultant at a integrator with 201-500 employees

In the CMDB configuration monitoring. Example, if there is a configuration on the wrong side of the network or there are changes that result in harm to our IT infrastructure, the solution should immediately fix it.

View full review »
SP
Security Team Leader at a tech services company with 11-50 employees

Our customers are noticing configuration available in the GUI interface and I think that they should be equal.

View full review »
GV
ICT Architect at a insurance company with 51-200 employees

Areas for improvement would be the ease of use and the integration with Fortinet's own products.

View full review »
GV
ICT Architect at a insurance company with 51-200 employees

The performance can be improved. Sometimes it takes a long time to fetch data. 

View full review »
Buyer's Guide
Fortinet FortiSIEM
April 2024
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
767,847 professionals have used our research since 2012.