We run a Manage Security Services company and we use it in-house and for some of our clients. The service is a multitenant platform where our clients can log on to view and access various security-related activities and features. In more ways, it becomes like a cloud solution to them. We make use of a secure connection from the clients’ networks using collectors located on their premises back to our centralized SIEM platform.
IT Executive: Operations & Security at Icon Information Systems (Pty) Ltd
The performance is very good, and it is extremely scalable
Pros and Cons
- "To add workers and even collectors is pretty easy."
- "The dashboard needs to improve."
What is our primary use case?
What is most valuable?
The most valuable feature is the differentiator, which has a combination of not only the SOC which covers the security operations aspect, but it also includes NOC capabilities. FortiSIEM uses PAM (Performance, Availability, and Monitoring) from an NOC perspective. So not only do you natively look at security data as most SIEM solutions, but you're also looking at the performance and the availability component of those devices. It's easy for us to coordinate if a security incident occurs. You're not only looking at security logs but you also looking at what could potentially have happened in terms of device performance. So that feature to me already makes it quite a big differentiator in the market, compared to other SIEM tools out there.
What needs improvement?
When they started out after acquiring AccelOps, the user interface wasn't that great. But from version 5.0 they have obviously radically changed the interface, aligning it to the rest of the Forti products from a user experience point of view. This means that there is constant improvement on the interface side of the solution. The other thing that I've noticed is when searching for very old incidents, there is a slight delay. It obviously has to pull that information from the backend database, and the key point to note is that it depends on how you set it up in the backend where factors such as disk types and disk array configs come into play.
For how long have I used the solution?
I have been using this solution for 18 months now.
Buyer's Guide
Fortinet FortiSIEM
June 2025

Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
What do I think about the stability of the solution?
The solution is quite solid and stable.
What do I think about the scalability of the solution?
The scalability component is easy. To add workers and even collectors is easy which is how we've deployed it, makes scalability much easier. We plan to grow our users into the thousands.
How are customer service and support?
I never really used support from Fortinet for the FortiSIEM solution that frequent because I figured most of the stuff out on my own, but that being said, the Fortinet Support is great because I figured most of the stuff out on my own.
How was the initial setup?
The initial setup was quite complex. We've had some issues with the first OVF file that we downloaded. We had to customize the installation processes. It was a bit complex in the earlier versions, but the newer versions have greatly improved.
What other advice do I have?
We use an on-premises deployment model from our perspective and a hybrid model from a customer/user perspective.
I will recommend this solution to others out there looking for a SIEM solution. I've already done a few events we were talk about FortiSIEM and its advantages. I do, however, think the main dashboard where you create and design your graphs could do with some improvement improved. On a scale from 1 to 10, I will rate this solution an 8 to ensure there’s continuous improvement.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Security Manager at BKL
Seamless integration with FortiGate, and has an easy setup, but is lacking user behavior analytics
Pros and Cons
- "The seamless integration with FortiGate is the solution's most valuable aspect."
- "When compared with some competitors, in terms of performance, the CPU and RAM requirements and the capability of coordination with development all need some improvement."
What is our primary use case?
We primarily use the solution for integration with FortiGate Firewall. We use it for multiple authentification, malware detection, and protection from DDoS attacks.
What is most valuable?
The seamless integration with FortiGate is the solution's most valuable aspect.
What needs improvement?
When compared with some competitors, in terms of performance, the CPU and RAM requirements and the capability of coordination with development all need some improvement.
The solution should offer user behavior analytics in a future release.
For how long have I used the solution?
I've been using the solution for two years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
We don't have any expansion requirements, so I've never looked into scalability.
How are customer service and technical support?
We've never reached out to technical support. If we need assistance, we typically look for FortiGate documents or scan their blog site. We handle any problems internally.
Which solution did I use previously and why did I switch?
We previously used an open-source solution called Elastic.
How was the initial setup?
The initial setup is easy.
What about the implementation team?
We received support from an integrator.
Which other solutions did I evaluate?
We evaluated AlienVault and SolarWinds. These were both within our limited budget, but we chose FortiSIEM because it integrated seamlessly with FortiGate firewall.
What other advice do I have?
We use the on-premises deployment model.
I'd recommend this solution to companies that have a FortiGate firewall and are on a limited budget.
I'd rate the solution six out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Fortinet FortiSIEM
June 2025

Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
Solutions Consultant at a comms service provider with 51-200 employees
A stable solution with good pricing, but they need to address recent changes to technical support
Pros and Cons
- "Both the collecting logs and duo correlation are valuable features for us."
- "The support of the product changed recently, and I don't think it's for the better. They should work to improve the support they offer to clients."
What is our primary use case?
We primarily use the solution for collecting logs and duo correlation on our customer's premises.
What is most valuable?
Both the collecting logs and duo correlation are valuable features for us.
Fortinet also offers very good pricing. Their pricing is incredible.
What needs improvement?
The support of the product changed recently, and I don't think it's for the better. They should work to improve the support they offer to clients.
They also have to improve their import perfection solution.
For how long have I used the solution?
I've been using the solution for 1.5 years.
What do I think about the stability of the solution?
The solution is very stable, like all Fortinet products.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and technical support?
Technical support is very good. They also provide you with additional materials to study the product by yourself so that you can get a better understanding of the full solution.
How was the initial setup?
The initial setup is complex, mostly because of the security, not because of the product. Most of the security features in the installation process are difficult. They require tuning. You have to be careful you don't configure something wrong. This is a complexity of the environment and the solution itself. The engineer should understand what the customer is looking for. The product might be very good, but if it is positioned in the wrong way, it can be harmful.
Which other solutions did I evaluate?
I did not evaluate other options; this solution was the decision of the customer. However, in the past, I have evaluated and worked with Splunk and IBM.
What other advice do I have?
We use the public cloud deployment model.
I like the product, and I would recommend it, but I much prefer Splunk.
The beautiful thing about Fortinet is that they have integrated many, many solutions. Their platform is very powerful. In the case of the customer, if he decides to choose Fortinet, he'll largely be stuck with that one vendor. Fortinet does integrate with a few other vendors, but it's best if you use only their solutions. It's more efficient, you have more manageability and you get more value that way.
I would rate the solution seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
An affordable all-in-one solution that's very stable
Pros and Cons
- "The solution is very stable. It's run for years without the need to do anything except, add new patches when they are available, which are always a good idea to install."
- "They could work on their documentation. If there's anything about the solution that needs improvement, it's that. For example, documentation already is on a very high level but specifically on the CLI there are tons of features which can be fine-tuned and thousands of commands are very difficult to document. If they could make this easier, it would improve the overall solution."
What is most valuable?
The solution has an all-in-one approach. We buy one product and everything our customer needs is included. He doesn't have to pay any additional licenses to get more functionality, so everything is there and if we have to do any adjustments, it's also done very quickly and easily.
What needs improvement?
The solution can't be improved, but it can be managed more clearly. The solution just needs minor improvements. I'm quite sure Fortinet is already working on this.
They could work on their documentation. If there's anything about the solution that needs improvement, it's that. For example, documentation already is on a very high level but specifically on the CLI, there are tons of features which can be fine-tuned and thousands of commands are very difficult to document. If they could make this easier, it would improve the overall solution.
For how long have I used the solution?
I've been using the solution for 1.5 years.
What do I think about the stability of the solution?
The solution is very stable. It has run for years without the need to do anything except, add new patches when they are available, which are always a good idea to install.
How was the initial setup?
The initial setup is quite easy.
What's my experience with pricing, setup cost, and licensing?
If we do an overall comparison with other products and also count additional licenses, which are necessary for other products, then the prices are comparative.
If we just leave it at base prices, for example, Splunk: Splunk is cheaper, but if you also count the price for licenses, reports, and other things - especially the megabytes and gigabytes of the lock data that you need - then it comes up to a much higher price than you have to pay for FortiSIEM which already includes these things in a base version.
What other advice do I have?
I would rate the solution nine out of ten. Our clients have been very happy with the solution.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
Manager, ICT Enterprise Services at a government with 201-500 employees
Has good business service summaries in the dashboards but it should have better integration abilities
Pros and Cons
- "Analytics is the most valuable feature. The business service summaries in the dashboards and the correlations for the SIEM are also valuable features."
- "Their product support, in general, is not that great. The product support is in the same ecosystem. Their support is improving but it's not that great.vvv"
What is our primary use case?
We use the on-prem deployment model of this solution. Our primary use case of this solution is for all of our infrastructure monitoring, applications, performance monitoring, and for security, incident, and event analysis.
What is most valuable?
Analytics is the most valuable feature. The business service summaries in the dashboards and the correlations for the SIEM are also valuable features.
What needs improvement?
Their product support, in general, is not that great. The product support is in the same ecosystem. Their support is improving but it's not that great.
It should also have better integration.
For how long have I used the solution?
I have been using FortiSIEM for four years.
What do I think about the stability of the solution?
It's a good product. It does what it is supposed to do.
What do I think about the scalability of the solution?
Scalability required a lot of training. If the training isn't adequate you cannot enjoy the end results.
There are currently around ten users using this solution. They are mostly system and network administrators using this solution. We don't have plans to increase the usage. We are going to switch to another product.
We require two staff members for the deployment and maintenance.
How are customer service and technical support?
When you log a call, you don't get instant replies or if there is a bug they take ages to fix it and they ask you to hold.
Which solution did I use previously and why did I switch?
We didn't previously use another SIEM solution.
How was the initial setup?
The installation is straightforward but the configuration is complex because it compromises of several aspects of the network infrastructure, servers, and the databases. You have to know what you want to gain out of this product.
The deployment took around three months. There are a lot of dashboards to configure. It's not about just the installation. The planning phase and understanding what you want to get out of it, setting up the logs, and working on the correlations take time.
What about the implementation team?
We used a local integrator for the deployment. They were good. When you consider the other SIEM products, this isn't a popular solution. When we implemented it, we were with the solution before it was acquired by Fortinet. It was a hassle.
What's my experience with pricing, setup cost, and licensing?
Licensing is a one time cost. If you want to enable different modules then there will be additional costs.
What other advice do I have?
Properly review this solution and your requirements. See how it will scale up to cloud requirements. Cloud technologies are becoming more prominent and you should see how you will be able to manage it with this tool.
It's a good product but you need to be well trained. If you don't have good training then you won't maximize the benefits of this product.
I would rate it a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
ICT Architect at a insurance company with 51-200 employees
CMDB database collects data from a lot of pre-configured devices
Pros and Cons
- "The most valuable feature is the dashboard. CMDB database collects data from a lot of pre-configured devices."
- "The performance can be improved. Sometimes it takes a long time to fetch data."
What is our primary use case?
We use the on-prem model of this solution. Our primary use case is for malware and behavior monitoring. We also use it to monitor system performance and user behavior.
What is most valuable?
The most valuable feature is the dashboard. CMDB database collects data from a lot of pre-configured devices.
What needs improvement?
The performance can be improved. Sometimes it takes a long time to fetch data.
For how long have I used the solution?
I have been using this solution for one and a half years.
What do I think about the stability of the solution?
It is very stable.
What do I think about the scalability of the solution?
Scalability is very good. We currently have 150 users using this solution. We don't have plans to increase usage at the moment.
What about the implementation team?
We implemented through Fortinet professional services. We were one of the first customers to implement the new version and it was a bit complex. I believe it has become easier. Deployment took them only a few hours. It didn't take a long time.
What other advice do I have?
I would rate it an eight out of ten. They should implement better behavior monitoring features to make it a perfect ten. It should also have better integration with their own products. They have a lot of interfaces for other products but it's not so easy to integrate their own devices.
I would recommend this solution to someone considering it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network and Security Administrator at PETRA Engineering Industries Co.
Hybrid Fortinet Fabric Solutions with a comprehensive view for all Fortinet products and a little support for other vendors
Pros and Cons
- "The interface is very easy to use. The connector in the core has FortiSIEM support from the vendor."
- "The nodes on our network did not comply with the SIEM solution. They use a different format parking log."
What is our primary use case?
We're using FortiSIEM as the main metadata server for all the security and infrastructure devices. We integrate a lot of nodes, switches, firewalls, and sandboxes with it to gain and covers performance, availability, change, and security monitoring aspects of network devices, servers, and applications.
How has it helped my organization?
FortiSIEM gives us a lot of valuable events and details by using a unified event-based framework to analyze all data including logs, performance monitoring data and provides a broad range of metrics.
What is most valuable?
The comprehensive view of the dashboard and the attribute base interface and the flexibility of implementation methods.
What needs improvement?
The Fortinet Fabric should be more easy more friendly to use. They use a different parsing log format.
for example Symantec ATP is not supported by FortiSIEM. Our reseller provided us FortiSIEM as a service. They should also provide us with a dashboard to monitor and to deploy a correlations.
I think fortinet should improve the AI correlations by combining advanced statistical and heuristic analysis with behavioral whitelisting .
For how long have I used the solution?
I have been using the solution around six months.
What do I think about the stability of the solution?
Stability is the main feature we had looked for because of our environment, i.e. why we chose FortiSIEM. The stability is good. We just install a connector on the supervisor outside.
With the stability of the connector, we faced some problems. The reseller asked us to reinstall the connector. The problem was with the reseller, not the connector.
How are customer service and technical support?
We used the solution's technical support for a lot of cases and tickets. Their responses are very good, kind, and quick.
Which solution did I use previously and why did I switch?
They have a poor correlation. They didn't use any new concepts like Fortinet. They just display the logs as it is with no attribute base.
How was the initial setup?
The initial setup with Fortinet FortiSIEM Accelops was not easy. We had faced a few problems. but I think Fortinet should give more training courses for their resellers.
We needed to find what the weak points were. in our network. Our deployment took up to two months.
We were looking to deploy a unique correlation between nodes. We wanted to track the packets from our clouds Services like cloud sandbox and anti-spam to log our end-to-end connections.
The reseller told us that they comply with our solution. After that, we figured out that it was not going to very easy. FortiSIEM doesn't support ATP Symantec.
They also did not support our web gateway log format.
What other advice do I have?
The interface is easy to use but initial setup is not . The connector in the core has FortiSIEM support from the vendor. FortiSIEM supports a lot of vendors. It is a good product for us.
I rank it as eight on a scale from one to ten. because It doesn't support a lot of vendors and also the FortiSIEM still not common to use with fortinet partner maybe they doesn't give adequate training.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Security Engineer at Spectrotel
Correlates incidents between products and notifies our SOC accordingly
Pros and Cons
- "It gives us the opportunity to generate notifications based upon rules that get triggered, and the rules could be specific to PCI, HIPAA, GIBA, NIST, and so forth."
- "The backup and recovery process for this solution needs improvement."
What is our primary use case?
We are a partner, and we use this solution to ingest our customers' syslogs data for their firewalls.
How has it helped my organization?
This solution allows us to ingest syslogs from Fortinet firewalls and other products into what we call FortiSIEM. This is a processor that correlates it with the event types and incidents. It gives us the opportunity to generate notifications based upon rules that get triggered, and the rules could be specific to PCI, HIPAA, GIBA, NIST, and so forth. All of these incidents are now correlated and sent up to a dashboard or emailed, where, as a SOC, we can review these incidents and triage the necessary resolution.
What needs improvement?
The backup and recovery process for this solution needs improvement.
I would like to see a database with more structure in terms of maintenance and ease of use. The process of creating is much simpler than that of duplication. The procedures are not proper for handling its PostgreSQL database.
For how long have I used the solution?
More than two years.
What do I think about the stability of the solution?
I would say that this solution is stable when it is configured and deployed by the Fortinet professional team.
What do I think about the scalability of the solution?
The scalability is there, and you can expand on the EPS (Events Per Second) as needed.
We do plan on selling this service to our customers that can see the benefit in it. We will probably introduce an incident response application to help triage incidents at a faster level.
How are customer service and technical support?
Technical support is very good. The people in support are excellent, and they know this product in and out. They are very quick to respond and the resolution is very quick.
How was the initial setup?
The initial setup for this solution is straightforward, although we are not yet in full production. During the past two years, while we have been implementing, we have found a lot of bugs in the software. As such, we're still not in a state where we can go into full production. For example, if you are certified for PCI then one of the standards is that you have to have proper backup recovery in place. This solution is lapsing in that area.
Two staff are required for deployment and maintenance.
What about the implementation team?
We used Fortinet consultants for the deployment.
What's my experience with pricing, setup cost, and licensing?
We bought the perpetual license, so we own the product, but there is a three-year support renewal fee for that.
Which other solutions did I evaluate?
We did evaluate Splunk before choosing this solution, but it was too much on the high end for our business model.
What other advice do I have?
We are very impressed with this product. However, they have to fix their backup and recovery procedure and provide a good DR service without charging for a secondary license.
I would rate this solution a seven and a half out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.

Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Security Information and Event Management (SIEM)Popular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Cortex XSIAM
Rapid7 InsightIDR
AlienVault OSSIM
Google Chronicle Suite
Securonix Next-Gen SIEM
ManageEngine Log360
Sentinel
Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?
- What Questions Should I Ask Before Buying SIEM?
- What are the pros and cons of internal SOC vs SOC-as-a-Service?