Try our new research platform with insights from 80,000+ expert users

Cribl vs Fortinet FortiSIEM comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
3.0
Cribl is cost-effective compared to Splunk, but not all users see clear returns in time and cost savings.
Sentiment score
1.0
Fortinet FortiSIEM delivers security improvements and customer satisfaction, leading to positive financial outcomes despite no explicit ROI measurement.
 

Customer Service

Sentiment score
5.0
Cribl's customer support is effective and prompt, with high satisfaction despite some noted areas needing improved understanding of customer needs.
Sentiment score
7.4
Fortinet FortiSIEM's customer service is seen as professional but has mixed reviews on response times and support accessibility.
The community, including the engineering and sales teams, is available on Slack and is very supportive.
Local tech support is available, however, for more critical or technical issues, we depend on the OEM directly, especially when it comes to on-prem solutions.
There is a knowledgeable, though small, team of support engineers around the world.
They take some time to respond because they need logs and investigations, which delays the response time.
 

Scalability Issues

Sentiment score
5.3
Cribl is highly scalable, enabling efficient workload distribution and quick deployment, appealing to businesses of all sizes.
Sentiment score
7.2
Fortinet FortiSIEM scales well, accommodating different business sizes but faces challenges with licensing, architecture, and configuration complexities.
I don't need to talk to a Cribl engineer to connect a new log source.
It is pretty scalable, just in terms of cost.
At any point in time, when network devices increase or there is a change in the infrastructure, we can add more workers and collectors to expand our infrastructure setup.
Fortinet FortiSIEM is highly scalable.
Fortinet FortiSIEM is easy to scale.
 

Stability Issues

Sentiment score
5.6
Cribl is stable and reliable, with quick bug resolution and improvements over time despite occasional connectivity issues.
Sentiment score
5.6
Fortinet FortiSIEM is reliable and stable, handling updates well, with users rating its performance highly despite occasional bugs.
If the pipeline is down and we receive an alert that it's not sending information to the log collection platform for more than one or two hours, if we receive an alert, it would be great.
It stabilizes itself in an appropriate time, so its uptime is good.
These issues may cause unusual errors and user interface issues.
Some stability issues occur, but Fortinet's technical support team provides assistance.
 

Room For Improvement

Cribl faces compatibility issues, UI limitations, and documentation inconsistencies, requiring enhancements in integration, customization, and data handling.
Fortinet FortiSIEM needs improvements in integration, user interface, support, cost, and features like AI and automated responses.
Perhaps more flexibility in terms of metrics would be helpful.
Fortinet FortiSIEM should broaden its remediation part to include more features for incident management.
Enhancing the completeness of its APIs could aid in better external integrations.
Recently, they revised it to a subscription-based, all-inclusive license.
 

Setup Cost

Cribl offers competitive pricing valued for cost-effectiveness and scalability, though its complex credit system can cause confusion.
Fortinet FortiSIEM provides flexible pricing that can be cost-effective, but costs may increase with additional modules and scalability.
Setting it up for oneself as an enterprise-licensed product can be quite expensive.
Windows agent licenses cost around 3,000 Rupees per device per year.
The revised model is subscription-based and more flexible.
 

Valuable Features

Cribl provides efficient, real-time data transformation and routing, supporting scalability, cost reduction, and rapid integration for enhanced operational efficiency.
Fortinet FortiSIEM provides automation, analytics, and integration with a user-friendly interface for efficient threat detection and network monitoring.
The community on Slack is excellent for solving questions and getting ideas.
It provides extensive logging and record-keeping for internal networks, cloud applications, and services as well as perimeter physical network security.
I find the real-time monitoring and correlation capabilities effective for security alerts.
 

Categories and Ranking

Cribl
Ranking in Security Information and Event Management (SIEM)
12th
Average Rating
8.4
Reviews Sentiment
6.2
Number of Reviews
15
Ranking in other categories
Application Performance Monitoring (APM) and Observability (14th), Log Management (8th), Observability Pipeline Software (1st)
Fortinet FortiSIEM
Ranking in Security Information and Event Management (SIEM)
7th
Average Rating
7.6
Reviews Sentiment
5.8
Number of Reviews
75
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2025, in the Security Information and Event Management (SIEM) category, the mindshare of Cribl is 1.0%, up from 0.2% compared to the previous year. The mindshare of Fortinet FortiSIEM is 3.3%, up from 3.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM)
 

Featured Reviews

Joe Cicero - PeerSpot reviewer
Facilitates seamless log integration and reduces data costs with efficient compression
My favorite feature is Cribl Stream. That's probably the only Cribl product I have a lot of experience with, and Cribl Stream makes it very easy to identify where all the customer's log sources are and to quickly connect them to a destination source such as Microsoft Sentinel and Microsoft Azure Data Storage. Cribl Stream does two things: not only does it make it easy to connect one log source or one dataset to multiple storage locations, but it also has compression features, which greatly reduce the storage cost for that data. It strips out and compresses data so that only the absolute information remains and not any duplicates. Dual destination and compression are the two top features.
Oliver Jackson - PeerSpot reviewer
Systems monitoring enhanced by firewall and intrusion detection features
My primary use case for Fortinet FortiSIEM is systems monitoring and alerting. I use it for standard functions like log monitoring, incident detection, and notification.  My customers are mostly medium-sized enterprises ranging from engineering companies, mining companies, independent schools, and…
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
865,384 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
17%
Computer Software Company
9%
Healthcare Company
8%
Manufacturing Company
7%
Computer Software Company
13%
Financial Services Firm
9%
Government
7%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What needs improvement with Cribl?
Something that Cribl could do better is processing time. There is not enough customization to improve performance. An example would be with AWS Lambda functions, the way we were doing it before. Th...
What is your primary use case for Cribl?
Our use cases that we are exploring Cribl for right now are for data parsing and data manipulation.
What do you like most about Fortinet FortiSIEM?
Fortinet FortiSIEM needs to provide better API integrations to users.
What is your experience regarding pricing and costs for Fortinet FortiSIEM?
The pricing is reasonable, which is why it is preferred by government customers. Windows agent licenses cost around 3,000 Rupees per device per year.
What needs improvement with Fortinet FortiSIEM?
Fortinet FortiSIEM should broaden its remediation part to include more features for incident management. Currently, to manage repetitive incidents or for remediation, I need to use a separate softw...
 

Comparisons

 

Also Known As

No data available
FortiSIEM, AccelOps
 

Overview

 

Sample Customers

Information Not Available
FortiSIEM has hundreds of customers worldwide in markets including managed services, technology, financial services, healthcare, and government. Customers include Aruba Networks, Compushare, Port of San Diego, Cleveland Indians, Infoblox, Healthways, and Referentia.
Find out what your peers are saying about Cribl vs. Fortinet FortiSIEM and other solutions. Updated: July 2025.
865,384 professionals have used our research since 2012.