We performed a comparison between Fortinet FortiSIEM and Fortra's Intermapper based on real PeerSpot user reviews.
Find out in this report how the two Security Information and Event Management (SIEM) solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."It is always correlating to IOCs for normal attacks, using Azure-related resources. For example, if any illegitimate IP starts unusual activity on our Azure firewall, then it automatically generates an alarm for us."
"Having your logs put all in one place with machine learning working on those logs is a good feature. I don't need to start thinking, "Where are my logs?" My logs are in a centralized repository, like Log Analytics, which is why you can't use Sentinel without Log Analytics. Having all those logs in one place is an advantage."
"One of the most valuable features is that it creates a kind of a single pane of glass for organizations that already use Microsoft software. So, when they have things like Microsoft 365, it is very easy for them to kind of plug in or enroll those endpoints into the Azure Sentinel service."
"The dashboard that allows me to view all the incidents is the most valuable feature."
"The most valuable features are its threat handling and detection. It's a powerful tool because it's based on machine learning and on the behavior of malware."
"It has a lot of great features."
"The AI and ML of Azure Sentinel are valuable. We can use machine learning models at the tenant level and within Office 365 and Microsoft stack. We don't need to depend upon any other connectors. It automatically provisions the native Microsoft products."
"Sentinel also enables you to ingest data from your entire ecosystem and not just from the Microsoft ecosystem. It can receive data from third-party vendors' products such firewalls, network devices, and antivirus solutions. It's not only a Microsoft solution, it's for everything."
"The most valuable feature is the dashboard. CMDB database collects data from a lot of pre-configured devices."
"Analytics is the most valuable feature. The business service summaries in the dashboards and the correlations for the SIEM are also valuable features."
"Technical support is helpful."
"The most valuable feature is the anomaly-reporting alarms."
"Fortinet FortiSIEM provides good detection against advanced threats."
"The solution’s IP database is awesome."
"The interface is very easy to use. The connector in the core has FortiSIEM support from the vendor."
"The product is quite well-organized. The GUI makes it easy to navigate."
"The most valuable features are its: log history, real-time monitoring capabilities, accuracy - the number of false positives is very low, and the mapping features."
"It's a nice graphical interface, a nice map, that relates Layer 1 to Layer 3, virtually instantly, to the Helpdesk support staff. It provides a default place to get critical information so we can deploy our staff."
"What is really cool about HelpSystems InterMapper is that because of its SNMP base, you can integrate all different makes and models on the same map. You, of course, can have more than one map, but you have an option to have visibility into the entire network from one centralized system. You can monitor IPs, routers, radios, DC power plants, and UPS. You can do it all from one network management and monitoring solution. That's what really makes HelpSystems Intermapper great. Another great thing about HelpSystems InterMapper is that you can really bundle different probes under one device. You can have a bundled device. You can monitor the physical status of a host based on the IP availability. You can also monitor services and actually see if anything happens. You can quickly determine whether it is the application layer, host layer, or network layer. HelpSystems Intermapper gives such a unique representation of a network. Ever since we started using HelpSystems InterMapper, we don't have to document everything in a detailed format and store it somewhere. Right now, it is really a combination of network topology, network monitoring, and network analyzing. So, in my opinion, it is awesome. When you have your SNMP topology defined, you don't require a dedicated NMS engineer to manage your system, which is another great thing about HelpSystems InterMapper. I see how our operators get so excited by having the ability to map a device or interface and connect interfaces together. HelpSystems InterMapper is also very operator friendly; not just user friendly, but also operator friendly. This is a unique feature, and it works really great."
"It's all today portal-based which is a good feature for us."
"They should just add more and more out-of-the-box connectors. It is quite a new product, and it has a lot of connectors, and even more would be good."
"Sometimes, we are observing large ingestion delays. We expect logs within 5 minutes, but it takes about 10 to 15 minutes."
"One key area that can be improved is by building a strong integration with our XDR platform."
"At the network level, there is a limitation in integrating some of the switches or routers with Microsoft Sentinel. Currently, SPAN traffic monitoring is not available in Microsoft Sentinel. I have heard that it is available in Defender for Identity, which is a different product. It would be good if LAN traffic monitoring or SPAN traffic monitoring is available in Microsoft Sentinel. It would add a lot of value. It is available in some of the competitor products in the market."
"Sentinel's reporting is complex and can be more user-friendly."
"They can work on the EDR side of things... Every time we need to onboard these kinds of machines into the EDR, we need to do it with the help of Intune, to sync up the devices, and do the configuration. I'm looking for something on the EDR side that will reduce this kind of work."
"They only classify alerts into three categories: high, medium, and low. So, from the user's point of view, having another critical category would be awesome."
"Microsoft Sentinel should provide an alternative query language to KQL for users who lack KQL expertise."
"The biggest thing that could be better is a quicker response to support cases."
"It would be good if the solution offered even more configuration options, especially in relation to the VPN so that it continues to be a very flexible option."
"The backup and recovery process for this solution needs improvement."
"With FortiSIEM, the issue has to do with the ways we can generate a report. It's not as flexible compared to that with other SIEM tools, like Splunk."
"Our customers are noticing configuration available in the GUI interface and I think that they should be equal."
"The graphs on the user interface could be improved as we often experience glitches."
"Patching is not great - we're not getting the support we'd expect."
"The log collection and configuration management are not great."
"They can do a better job with SLA reporting. It does some basic reporting, but it really doesn't offer the ability to monitor devices by groups, customers, or carrier to give an overall health performance of specifically-defined environments. That's where HelpSystems Intermapper could have done a better job. I would love to see advanced SLA monitoring and reporting in this solution. They already have a lot of ingredients. They already have SNMP polling. It is really about what people are looking for from SLA monitoring, especially someone who looks at the network topology. You want to see your endpoints. You want to see half of your endpoints by simply analyzing ICMP or SNMP-based availability of your endpoints. Having an ability to define your group and how you bring devices into your group would be a huge benefit."
"It's a smaller solution so tools are not as advanced as you would find in a larger solution"
"I'd love to see more of the network management side of it coming back into it. If we were able to run scripts to bounce ports on switches, that would be great. It's asking a lot, but it's actually very doable because I do it through scripting into other products. If we could incorporate that directly into Intermapper, that would be fantastic."
Earn 20 points
Fortinet FortiSIEM is ranked 8th in Security Information and Event Management (SIEM) with 63 reviews while Fortra's Intermapper is ranked 77th in Network Monitoring Software. Fortinet FortiSIEM is rated 7.6, while Fortra's Intermapper is rated 8.2. The top reviewer of Fortinet FortiSIEM writes "It's cheaper than other solutions with the same features but lacks integration with many third-party vendors". On the other hand, the top reviewer of Fortra's Intermapper writes "It tremendously cuts down our troubleshooting timeframe, but needs advanced SLA monitoring and reporting". Fortinet FortiSIEM is most compared with IBM Security QRadar, Splunk Enterprise Security, LogRhythm SIEM, Wazuh and ThousandEyes, whereas Fortra's Intermapper is most compared with . See our Fortinet FortiSIEM vs. Fortra's Intermapper report.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.