Fortinet FortiSIEM Valuable Features

HamedWasel - PeerSpot reviewer
Senior Network Security Engineer at Orange

FortiSIEM sends an email or SMS notifications to admins when there are significant incidents. It's a highly efficient way of responding to incidents. 

View full review »
Babar Shahbaz - PeerSpot reviewer
Head of Product Management (Cloud & Digital) at Pakistan Telecommunication Company Limited

Fortinet has a unique model, which they call MSSP, managed services security partner. They select a telco in a country, partner with them, and offer them the certification track. We are an MSSP partner in Pakistan. FortiSIEM and FortiSOAR, their overall solutions that are there for threat mitigation, visibility, control, et cetera, is well integrated.

We like the integration of all of these Fortinet platforms together. Everything is integrated well, and we are able to sell that as a service to our customers.

There's a VR feature that is basically segmenting these firewalls, these security devices. Using that feature, we can make a network slice for each and every enterprise customer. All of the infrastructure is deployed in our data center, yet customer uses it as if it is their own.

View full review »
SrikanthS - PeerSpot reviewer
Senior Manager - Technical at Sify Technologies

The solution’s IP database is awesome. If we get malicious IP attacks in the firewall, the solution has a validated database to mark IPs as malicious and generate an alert. We need not use any third-party solution.

View full review »
Buyer's Guide
Fortinet FortiSIEM
April 2024
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,578 professionals have used our research since 2012.
Ali Mohamed - PeerSpot reviewer
Account Manager at Cairo International Airport Co.

FortiSIEM's log correlation is good. 

View full review »
VA
CISO at a financial services firm with 501-1,000 employees

The product kicks the logs automatically without an agent. We also use it for file integrity monitoring. The analytics engine is quite good. It can correlate traffic across our various platforms and give us a standard dashboard view of what's happening. By seeing what's happening on the network, we can pick anomalies like encrypted traffic, policy violations, and unusual accesses. It helps us be compliant. We can push back on the users and the IT team and keep them accountable based on what they are doing across their network.

Real-time monitoring makes life quite easy for me. Once I have the assurance that I have visibility into what's happening, I can report to the business and my boss that all is well. It also allows me to keep the security operations team on its toes. We do a lot of red teaming. It allows us to see whether the SOC team is doing what it is supposed to do.

The tool is relatively easy to integrate. It's agentless. We have a Windows environment majorly. We can tell the product to monitor everything at once. As long as it's authenticated, it will fix what we need.

View full review »
ZaidoonAbuhanak - PeerSpot reviewer
SALES PRODUCT MANAGER at NOURNET

The pricing is good. 

The best features are the dashboard and the integration between the Fortinet products. We can connect the nodes very easily.

The initial setup is very easy.

It's great to use both this and FortiSOAR. It makes everything better. If you use them together with Fortianalyzer, it's better than Splunk.

The solution is stable. 

It is a scalable product. 

Technical support is helpful. 

View full review »
CO
Senior Network Associate at AMCON, Inc.

I like the reporting model where you can drill-down capabilities into user actions on the network.

I also like CMDB. The CMDB captures devices as long as they have SNMP enabled. It captures the information for me. 

View full review »
SrikanthS - PeerSpot reviewer
Senior Manager - Technical at Sify Technologies

Fortinet FortiSIEM has its own validated and authentic IP database that marks malicious IP attacks against the firewall and generates an alert for the same.

View full review »
RE
Director, Infrastructure and Operations at a comms service provider with 11-50 employees

The event correlation is pretty robust. The GUI is pretty good. 

View full review »
Alain ClovisBapfunya - PeerSpot reviewer
Cyber Security Specialist at EAST-NB

I like FortiSIEM because it integrates natively with our other Fortinet solutions and the Fortinet Fabric, but it also integrates with Cisco, Palo Alto and other security fabrics. 

View full review »
Ijeoma Nkemjika - PeerSpot reviewer
Customer Success Manager at Digitank Technology

Fortinet FortiSIEM provides good detection against advanced threats.

View full review »
AB
Solution Consultant at 1&1 Versatel Deutschland GmbH

FortiSIEM is a great tool for making security processes transparent. 

View full review »
SI
Principal Cloud Architect at Viria Security Oy

I think the most valuable feature is the easy alert setup, it's very important. It's quite simple to use and enables us to have different alerts in different categories. SOC is able to see all the red alerts, it's impossible to miss them. It's a good tool for analysis and for SOC. We upload all network detection tools that support FortiSIEM and can investigate for different alerts or vulnerabilities. A great feature is that you can use Python scripting for data stack. It's great for devices that don't generate a genuine local source of information. 

View full review »
Niranjan Singh - PeerSpot reviewer
Principal Solution Architect- Security & Privacy at Sify Technologies

Fortinet FortiSIEM is less costly than other products and is available 24/7.

View full review »
Kumar Vaibhav - PeerSpot reviewer
Solutions Architect at In2IT Technologies

The most valuable feature of Fortinet FortiSIEM is the user and entity behave as analytics(UEBA). This feature mixes your data and provides useful information based on the behavior of the targeted.

View full review »
TamimKhan - PeerSpot reviewer
Solution Architect at Tiger IT Bangladesh Limited

The solution's ability to collect data from different sources is its most valuable feature.

View full review »
Stefan Bächer - PeerSpot reviewer
IT Security & CyberSecurity Consultant at digitalDefense Information Systems GmbH

It works exceptionally well when combined with a vulnerability management solution.

View full review »
AK
Asst Programmer Data Center at a consultancy with 10,001+ employees

I like the Threat Hunting feature which provides complete traffic analysis, like file movement and processes. It's a good feature. 

View full review »
HO
Research Associate at a comms service provider with 1,001-5,000 employees

Fortinet FortiSIEM combines the SOC and NOC into a single solution with a single pane of glass. This feature on its own is next level and its easy to handle.

View full review »
AK
Asst Programmer Data Center at a consultancy with 10,001+ employees

We have found the most important features in Fortinet FortiSIEM to be the correlation, file utility check, latest file, and hash changes. These features are important for us.

View full review »
Abdul-MuminIddrisu - PeerSpot reviewer
CCO at oduma solutions ltd

Fortinet FortiSIEM's most valuable feature is the simplicity in handling multi-tenancy and the ability to switch between different clients at the same time. That was handled flawlessly.  

View full review »
SM
Network Security Engineer at Go Faster

Every feature is good. This is one of the greatest SIEM products on the market. The most valuable feature this solution offers is that it protects the server and the client.

It's very easy for anyone to work with. You don't need any help externally.

View full review »
RN
Cyber Security Analyst at a retailer with 1,001-5,000 employees

I like the various options, including the option for CMDB and the easier access to create rules, playbooks, or use cases. It's also easier to use for creating dashboards and reports.

View full review »
RO
Infrastructure Operations Manager at a computer software company with 501-1,000 employees

I’ve used Accelops in multiple different capacities and at several organizations. As far as my current role, I am an operations manager, and it gives me operational oversight. There are things like dashboards and reports (pre-configured and custom) that let me know that things are operating the way they should be, and when they are not. Reports and Alerts help identify security risks, identify performance problems, and help in capacity planning.

View full review »
MC
Presales IT at a tech services company with 201-500 employees

FortiSIEM has been a good product. It does everything that it has promised that it can do. It has been very useful to discover new threats from the outside such as external exploits, brute-force, or password tries. 

View full review »
SY
Senior Product Manager at a financial services firm with 201-500 employees

The most valuable feature of Fortinet FortiSIEM is the correlation of many events.

View full review »
it_user404364 - PeerSpot reviewer
Information Security Officer at a aerospace/defense firm with 10,001+ employees
  • Visibility
  • Flexibility
View full review »
it_user404421 - PeerSpot reviewer
Associate Director, Network Services at a university with 1,001-5,000 employees

The primary valuable feature is that it has replaced a whole lot of other products with one platform. That's a huge win right there. It can take logs from all my devices agentlessly and correlate data. It already has a lot of the advanced analytics and dashboards that we need already built-in.

Accelops is also well positioned within the industry, for example, by partnering with Octave which we're using as a login index for Accelops. We're able to bring up a security operations center, which helps a lot of the newer information security people.

View full review »
it_user276174 - PeerSpot reviewer
Director of IT with 501-1,000 employees

The security notifications and monitoring features.

View full review »
DD
Network Security Engineer at Technicom Mali

We already have experience with Fortinet products, so dealing with Fortinet FortiSIEM is not complicated.

View full review »
SC
Head - IT & SWIFT at a financial services firm with 1-10 employees

FortiSIEM's best features are the dashboards and customization.

View full review »
MB
chief of cybersecurity at ECSSA El Salvador

One of the most valuable features is that we can combine SOC and NOC operations in the same tool. We can provide NOC and SOC services in the same tool for two separate teams.

There are plenty of third-party solutions that integrate with FortiSIEM. All these solutions already have a ready integration, and we have the possibility to create a custom connector for these solutions. Its reports are also very good.

View full review »
TA
Security Manager at BKL

The seamless integration with FortiGate is the solution's most valuable aspect.

View full review »
it_user390012 - PeerSpot reviewer
Manager, Security Services at a financial services firm with 5,001-10,000 employees

The most valuable features for us are the built-in reports and alerts, along with the extreme flexibility in reporting and rule generation. The logs and search engine are also valuable features.

View full review »
Termphong Tana - PeerSpot reviewer
Assistant to Vice President at IT Green Public Company Limited

The most valuable features of Fortinet FortiSIEM are the SD-WAN, Global LAN, and application controls.

View full review »
it_user293910 - PeerSpot reviewer
Senior Enterprise Information Security Architect at a healthcare company with 1,001-5,000 employees
  • The automation piece -- its ability to dynamically discover which services need to be monitored and to automatically setup the appropriate monitoring.
  • We also like the intelligence behind the alerting; we like the out-of-the-box rules that don’t require a lot of tuning.
  • The product doesn’t require a lot of manpower, so there isn’t a lot of tuning or management overhead required for it.
View full review »
AK
Asst Programmer Data Center at a consultancy with 10,001+ employees

There's a great feature on the solution that allows us to analyze security issues and incidents. It automatically allows us to trace any incident. It's an invaluable aspect of the solution. 

The solution has a relatively low cost.

We find the solution to be stable.

It's my understanding that the solution can scale well.

View full review »
IS
Security Analyst at netfiniti

The solution is quite user-friendly.

It's very easy to configure everything, including the VPN. It gives you lots of good options.

The product is quite well-organized. The GUI makes it easy to navigate.

View full review »
SC
Partner at a security firm with 11-50 employees

Most of those CM functions and the correlation alerts are very helpful to our clients. 

The network monitoring is one of the most valuable aspects of the solution.

You can scale the solution with ease if you need to expand.

The stability is very reliable. It offers very good performance.

View full review »
AH
Solutions Consultant at a comms service provider with 51-200 employees

Both the collecting logs and duo correlation are valuable features for us.

Fortinet also offers very good pricing. Their pricing is incredible.

View full review »
AK
Manager, ICT Enterprise Services at a government with 201-500 employees

Analytics is the most valuable feature. The business service summaries in the dashboards and the correlations for the SIEM are also valuable features. 

View full review »
SJ
Senior Security Engineer at a tech services company with 1,001-5,000 employees

FortiSIEM provides a single PIN to monitor SOC and NOC. It's a nice tool for integration and monitoring. It provides multiple categories for monitoring based on security designations like low, medium, and high. 

View full review »
PD
Assistant Engineer at Harel Mallac Technologies Ltd

The solution is easy to use and user-friendly.

View full review »
HW
System Engineer / Network Consultant at a tech services company with 51-200 employees

The solution has an all-in-one approach. We buy one product and everything our customer needs is included. He doesn't have to pay any additional licenses to get more functionality, so everything is there and if we have to do any adjustments, it's also done very quickly and easily.

View full review »
MK
Technical manager at a tech services company with 11-50 employees

Fortinet FortiSIEM is easy to use.

View full review »
NW
Chief Technical Officer at a computer software company with 51-200 employees

The CMDB and the device discovery features are most valuable.

View full review »
JG
IT Executive: Operations & Security at Icon Information Systems (Pty) Ltd

The most valuable feature is the differentiator, which has a combination of not only the SOC which covers the security operations aspect, but it also includes NOC capabilities. FortiSIEM uses PAM (Performance, Availability, and Monitoring) from an NOC perspective. So not only do you natively look at security data as most SIEM solutions, but you're also looking at the performance and the availability component of those devices. It's easy for us to coordinate if a security incident occurs. You're not only looking at security logs but you also looking at what could potentially have happened in terms of device performance. So that feature to me already makes it quite a big differentiator in the market, compared to other SIEM tools out there.

View full review »
it_user277014 - PeerSpot reviewer
Systems Administrator with 501-1,000 employees

The granular monitoring capabilities. Also, it's very configurable.

View full review »
HH
Cybersecurity Engineer at a tech services company with 11-50 employees

The advanced agents used to collect logs have been most valuable. We have also made use of the advanced intelligence this solution offers.

View full review »
it_user275922 - PeerSpot reviewer
Network Engineer at a sports company with 51-200 employees

The ability to write my own parsers for the devices that are not supported by Fortinet is the most valuable feature. It’s impossible to find an application that supports every device/manufacturer that we have. Thus, being able to write my own parsers for device logs, allows for greater scalability.

View full review »
RP
Security Engineer L1 at a media company with 11-50 employees

It's a very nice solution to work with. It is easy to understand.

View full review »
it_user284157 - PeerSpot reviewer
Senior Network Security Architect at a retailer with 1,001-5,000 employees

The primary thing I use it for is monitoring IPS because we have 12 or 14 Cisco IPS devices, and the Cisco solution for monitoring that many IPS devices is hokey at best, aside from it being expensive. I also use it when we’re trying to track down activity on a particular IP address – I use the query engine to search for things like that.

View full review »
it_user1020687 - PeerSpot reviewer
Network and Security Administrator at PETRA Engineering Industries Co.

The comprehensive view of the dashboard and the attribute base interface and the flexibility of implementation methods.

View full review »
WM
Technical Lead at Arcon Labs at a tech services company with 51-200 employees

AccelOps can handle a lot of data and it's just so important to true monitoring. That is the strong point of AccelOps.

The second one is detecting. I can create a lot of rules to detect anything I like, and this is another strong point.

It's also the only SIEM platform on the market that has health monitoring capabilities, and correlates. For example, if a service is going down I can detect that it is going down and correlate it. For example, if it's because of an exploit can correlate this. It's a nice feature.

View full review »
it_user293913 - PeerSpot reviewer
IT Security and Compliance Officer at a energy/utilities company with 501-1,000 employees
  • Log correlation
  • Alerting
View full review »
it_user675411 - PeerSpot reviewer
Senior Technical Consultant at a integrator with 201-500 employees

Analytics. It can provide log information from the device. With log information, I can see if there is a threat

View full review »
GV
ICT Architect at a insurance company with 51-200 employees

The most valuable feature is the anomaly-reporting alarms.

View full review »
GV
ICT Architect at a insurance company with 51-200 employees

The most valuable feature is the dashboard. CMDB database collects data from a lot of pre-configured devices. 

View full review »
Buyer's Guide
Fortinet FortiSIEM
April 2024
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,578 professionals have used our research since 2012.