

Fortinet FortiSIEM and CrowdStrike Falcon Insight XDR are prominent competitors in the security solutions category. CrowdStrike Falcon Insight XDR appears to have a slight advantage due to its effective threat hunting and real-time alert capabilities, despite its higher cost.
Features: Fortinet FortiSIEM focuses on automation, dynamic discovery of services, and comprehensive security logging. It features out-of-the-box rules that require minimal tuning and integrates with diverse security platforms. CrowdStrike Falcon Insight XDR offers endpoint protection with lightweight agents, real-time alerts, and behavior-based threat detection, enhancing its threat-hunting effectiveness.
Room for Improvement: Fortinet FortiSIEM could enhance integration capabilities, improve API support, and create more user-friendly dashboards. Its complex initial setup and need for more intuitive reports and documentation are areas of concern. CrowdStrike Falcon Insight XDR should work on dashboard customization, tool integration, and reducing false positives, as its current high cost poses challenges for smaller businesses.
Ease of Deployment and Customer Service: Fortinet FortiSIEM is adaptable across deployment environments but critiqued for complex setup and slow technical support. CrowdStrike Falcon Insight XDR excels in public cloud deployment with efficient setup and robust support, though consistent customer service needs enhancement.
Pricing and ROI: Fortinet FortiSIEM is competitive and cost-effective against higher-end solutions, though deemed expensive in certain markets. CrowdStrike Falcon Insight XDR, positioned at a premium, offers significant security enhancements justifying its cost. Both products align their pricing with distinct market segments, offering value based on specific security needs.
CrowdStrike Falcon saves time and offers good value for money, especially for enterprise companies, because it can stop breaches.
It's very easy to deploy without many IT admins, saving time.
On a scale of one to ten, I would rate the technical support as a 10 because they resolve many issues for us.
The CrowdStrike team is very efficient; I would rate them ten out of ten.
They could improve by initiating calls for high-priority cases instead of just opening tickets.
Local tech support is available, however, for more critical or technical issues, we depend on the OEM directly, especially when it comes to on-prem solutions.
There is a knowledgeable, though small, team of support engineers around the world.
They take some time to respond because they need logs and investigations, which delays the response time.
It has adequate coverage and is easy to deploy.
In terms of scalability, I find CrowdStrike to be stable, and I have not encountered any limitations with it.
There's no scalability limitation from CrowdStrike itself, as it just requires agent deployment.
At any point in time, when network devices increase or there is a change in the infrastructure, we can add more workers and collectors to expand our infrastructure setup.
Fortinet FortiSIEM is highly scalable.
Fortinet FortiSIEM is easy to scale.
I have never seen instability in the CrowdStrike tool.
We are following N-1 versions across our environment, which is stable.
The biggest issue occurred when every computer worldwide experienced a blue screen.
It stabilizes itself in an appropriate time, so its uptime is good.
These issues may cause unusual errors and user interface issues.
Some stability issues occur, but Fortinet's technical support team provides assistance.
Simplifying the querying process, such as using double quote queries or directly obtaining logs based on IP addresses or usernames, would be beneficial.
Another concern is CrowdStrike's GUI. It changes annually, making it hard to work and find options.
Threat prevention should be their first priority.
Recently, they revised it to a subscription-based, all-inclusive license.
The built-in APIs in Fortinet FortiSIEM are somewhat lacking and could be improved for better integration with external ITSM products.
Fortinet FortiSIEM should broaden its remediation part to include more features for incident management.
It is expensive compared to SentinelOne, but as the market leader, it is worth it.
The licensing cost and setup costs are affordable.
The solution is a bit expensive.
Setting it up for oneself as an enterprise-licensed product can be quite expensive.
Windows agent licenses cost around 3,000 Rupees per device per year.
The revised model is subscription-based and more flexible.
I can investigate by accessing the customer's host based on the RTR environment and utilize host search to know details for the past seven days, including logins, processes, file installations, malicious processes, and network connections.
The real-time analytics aspect of CrowdStrike performs well because we get all logs in real-time, with no delay, allowing us to take action immediately.
Being an EDR solution, it helps us identify attacks in real-time.
It provides extensive logging and record-keeping for internal networks, cloud applications, and services as well as perimeter physical network security.
I find the real-time monitoring and correlation capabilities effective for security alerts.
| Product | Mindshare (%) |
|---|---|
| CrowdStrike Falcon | 2.7% |
| Fortinet FortiSIEM | 2.2% |
| Other | 95.1% |

| Company Size | Count |
|---|---|
| Small Business | 54 |
| Midsize Enterprise | 34 |
| Large Enterprise | 63 |
| Company Size | Count |
|---|---|
| Small Business | 34 |
| Midsize Enterprise | 22 |
| Large Enterprise | 24 |
CrowdStrike Falcon Insight XDR provides adversary-driven detection and response across endpoints and beyond. It combines AI-powered endpoint detection and response with integrated threat intelligence and expert context to deliver high-quality, context-rich detections that help security teams identify and prioritize sophisticated threats.
Automated leads and Charlotte AI, combined with attack-path visibility, adversary context and MITRE ATT&CK mappings, help analysts investigate incidents faster. Real Time Response and Falcon Fusion SOAR support direct and automated remediation at scale. Extend investigations with critical context from identity, cloud, mobile and data protection, while incorporating third-party data in the same console.
What are the key features of CrowdStrike Falcon?
What benefits and reported outcomes can organizations achieve?
In technology sectors, CrowdStrike Falcon commonly supports endpoint protection and threat response initiatives, allowing companies to replace traditional antivirus systems with more advanced solutions. In finance, it secures sensitive data across multiple platforms, ensuring compliance. In healthcare, real-time security analysis protects patient data on critical devices like servers and laptops, utilizing AI to enhance cybersecurity defenses.
Fortinet FortiSIEM offers robust features like automation, real-time monitoring, and scalable log correlation. It integrates SOC and NOC, enhancing security by seamlessly managing data. A preferred choice for threat management, its comprehensive reports and competitive pricing add value.
Fortinet FortiSIEM serves as a comprehensive platform for security monitoring, threat detection, and incident management. It streamlines operations by integrating seamlessly with Fortinet and third-party tools, offering dynamic service discovery and user-friendly analytics. Leveraging its stable infrastructure, organizations conduct log analysis and behavioral monitoring across networks and applications. It supports compliance reporting and enhances security environments through integration with firewalls and security devices. Its cloud and on-premise options cater to regulatory and operational needs, while multitenant capabilities enable managed security service providers to extend robust security services. Users have highlighted areas for improvement in API integration, data retrieval speed, resource consumption, automation, and reporting flexibility.
What are the key features of Fortinet FortiSIEM?In healthcare, Fortinet FortiSIEM ensures compliance and secure health data management. Financial institutions utilize it for real-time monitoring and fraud detection, while educational sectors deploy for network security and data integrity. Service providers leverage its multitenant features for expansive client management.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.