The most valuable features for us are the built-in reports and alerts, along with the extreme flexibility in reporting and rule generation.
Fortinet FortiSIEM offers flexible reporting and rule generation with built-in reports and alerts, integrating SOC and NOC operations for robust monitoring. Seamless integration with platforms like Cisco and Palo Alto enhances interoperability. It provides strong event correlation for threat detection, but creating parsers for unsupported devices is cumbersome. Documentation needs improvement, especially on CLI features, and integration can be challenging. Technical support is often criticized, and the licensing model is seen as expensive.