it_user284157 - PeerSpot reviewer
Senior Network Security Architect at a retailer with 1,001-5,000 employees
Vendor
It helps us identify the origin of a DoS attack, where it came from, how long it lasted, how intense it was, etc. and take the appropriate action.

What is most valuable?

The primary thing I use it for is monitoring IPS because we have 12 or 14 Cisco IPS devices, and the Cisco solution for monitoring that many IPS devices is hokey at best, aside from it being expensive. I also use it when we’re trying to track down activity on a particular IP address – I use the query engine to search for things like that.

How has it helped my organization?

We’ve had some situations where we’ve either gotten hit with a DOS attack or we’ve gotten notification that we’ve been blacklisted because some IP that belongs to us is roaming the internet trying to bogusly log in to SNMP servers. So, we’ll take that IP, or wherever the DoS is coming from, and run a query over the last 30 days or so, to see just what the activity on that machine has been, and make various decisions from that. In a couple of cases it’s meant to shut down the machines and get them off the network because they’ve obviously got some kind of malware on them. In other cases, it’s been a matter of determining the exact scope of DoS – where it came from, how long it lasted, how intense it was, etc.

What needs improvement?

One of the things that actually opened a ticket about (and they couldn’t help me) is when traffic is leaving our network, it’ll only report the source. I would think that if it’s examining the packets that it should also be able to give me the destination. It’s not possible to tell me whether it reached the destination, but it would be helpful to know where it was headed when it left the network. That field is always empty in the query.

For how long have I used the solution?

I've used it for about a year.

Buyer's Guide
Fortinet FortiSIEM
May 2024
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
769,789 professionals have used our research since 2012.

What was my experience with deployment of the solution?

No serious issues.The biggest issue I had with their deployment methodology as a virtual appliance – with the way things our VM farms are structured – there are only a couple of people that are allowed to bring up OVAs, which is the way they ship the product, so I have to get their time to do any kind of upgrade.That’s why I recently queried the helpdesk on what was required to do the upgrade that’s available to us (at no cost), and they pointed me to a manual which I haven’t had time to download yet. My guess is I’m going to have to deploy a separate OVA.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

We've not had any issues so far.

How are customer service and support?

Customer Service:

The only complaint I have is that they wouldn’t issue a license until they had the check in their hands, which is not my experience with other vendors. If you issue a PO for something, usually you get a license immediately – in their case they wouldn’t until they had actually gotten payment, which was a little frustrating.

Technical Support:

I have tried to open some tickets, and usually they’ll respond with a note at the top of the response. It says “if you’re responding to this email do it above this line,” and I didn’t see that the first time I got an email like that, so for weeks they kept sending me emails saying I hadn’t responded to their initial contact. To me that was a little bit nit-picky.

Which solution did I use previously and why did I switch?

I inherited a solution that was discontinued by the vendor, and I was charged with finding a replacement.

How was the initial setup?

Once we got the OVA file, and I was able to commandeer some time from the appropriate people here, it wasn’t an issue.

What about the implementation team?

It was in-house. Part of the initial purchase included some on-site time with one of their engineers, so I used that time to do an upgrade while he was here.

What's my experience with pricing, setup cost, and licensing?

The pricing seems fairly standard in terms of the pricing model, so how it compares to other similar products I don’t know. The people I took this to about replacing the other product didn’t seem to blink at the price.

Which other solutions did I evaluate?

We ran a PoC for Accelops for a trial period, so we didn’t look as much into other products.

What other advice do I have?

It would be to get as good an estimate as you can of what EPS's you’ll need before you get pricing and so forth. We underestimated what we would need, which is what precipitated ordering additional licensing and not being able to get them right that.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
PeerSpot user
Network and Security Administrator at PETRA Engineering Industries Co.
Real User
Hybrid Fortinet Fabric Solutions with a comprehensive view for all Fortinet products and a little support for other vendors
Pros and Cons
  • "The interface is very easy to use. The connector in the core has FortiSIEM support from the vendor."
  • "The nodes on our network did not comply with the SIEM solution. They use a different format parking log."

What is our primary use case?

We're using FortiSIEM as the main metadata server for all the security and infrastructure devices. We integrate a lot of nodes, switches, firewalls, and sandboxes with it to gain and covers performance, availability, change, and security monitoring aspects of network devices, servers, and applications.

How has it helped my organization?

FortiSIEM gives us a lot of valuable events and details by using a unified event-based framework to analyze all data including logs, performance monitoring data and provides a broad range of metrics.

What is most valuable?

The comprehensive view of the dashboard and the attribute base interface and the flexibility of implementation methods.

What needs improvement?

 The Fortinet Fabric should be more easy more friendly to use. They use a different parsing log format.

for example Symantec ATP is not supported by FortiSIEM. Our reseller provided us FortiSIEM as a service. They should also provide us with a dashboard to monitor and to deploy a correlations.

I think fortinet should improve the AI correlations by combining advanced statistical and heuristic analysis with behavioral whitelisting .

For how long have I used the solution?

I have been using the solution around six months.

What do I think about the stability of the solution?

Stability is the main feature we had looked for because of our environment, i.e. why we chose FortiSIEM. The stability is good. We just install a connector on the supervisor outside. 

With the stability of the connector, we faced some problems. The reseller asked us to reinstall the connector. The problem was with the reseller, not the connector.

How are customer service and technical support?

We used the solution's technical support for a lot of cases and tickets. Their responses are very good, kind, and quick. 

Which solution did I use previously and why did I switch?

They have a poor correlation. They didn't use any new concepts like Fortinet. They just display the logs as it is with no attribute base.

How was the initial setup?

The initial setup with Fortinet FortiSIEM Accelops was not easy. We had faced a few problems. but I think Fortinet should give more training courses for their resellers.

We needed to find what the weak points were.  in our network. Our deployment took up to two months. 

We were looking to deploy a unique correlation between nodes. We wanted to track the packets from our clouds Services like cloud sandbox and anti-spam to log our end-to-end connections.

The reseller told us that they comply with our solution. After that, we figured out that it was not going to very easy. FortiSIEM doesn't support ATP Symantec. 

They also did not support our web gateway log format.

What other advice do I have?

The interface is  easy to use but initial setup is not . The connector in the core has FortiSIEM support from the vendor. FortiSIEM supports a lot of vendors. It is a good product for us.

I rank it as eight on a scale from one to ten. because It doesn't support a lot of vendors and also the FortiSIEM still not common to use with fortinet partner maybe they doesn't give adequate training.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Fortinet FortiSIEM
May 2024
Learn what your peers think about Fortinet FortiSIEM. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
769,789 professionals have used our research since 2012.
Technical Lead at Arcon Labs at a tech services company with 51-200 employees
Real User
It's complicated to deploy but detection rules are flexible
Pros and Cons
  • "AccelOps can handle a lot of data and it's just so important to true monitoring. Also, I can create a lot of rules to detect anything I like."
  • "Does not have load-sharing or high-availability, and these are important things to implement. I can do the same things in another way, but not naturally having these features makes it complicated."

What is our primary use case?

My primary use case is that it is an analyst tool for hunting on your site network.

How has it helped my organization?

The platform is nice. It is not easy to implement, but once you do so, there is a lot of value from the platform. 

What is most valuable?

AccelOps can handle a lot of data and it's just so important to true monitoring. That is the strong point of AccelOps.

The second one is detecting. I can create a lot of rules to detect anything I like, and this is another strong point.

It's also the only SIEM platform on the market that has health monitoring capabilities, and correlates. For example, if a service is going down I can detect that it is going down and correlate it. For example, if it's because of an exploit can correlate this. It's a nice feature.

What do I think about the stability of the solution?

I think all SIEM platforms have a problem handling a lot of data. My response is "it depends." Depends on the people, depends on the product, depends on the technology. To implement any technology you need good people, and this is independent of the label of the company or technology. The stability is not bad, it's not good. It's a complicated question.

What do I think about the scalability of the solution?

I don't have any feature for load-sharing or high-availability, and these are important things to implement. I can do the same things in another way, but not naturally having these features makes it complicated. For example, the design is bad because you have one supervisor on one machine and you handle everything off this machine supervisor. It is a design problem. The technology also has limitations because you have a lot of memory and a lot of processors, but you have a limit with processors and memory, which causes problems with scalability. 

How are customer service and technical support?

It's equal to any technical support. You need to go to level one, level two, level three to reach their engineers. It is complicated. With any technology it is like this. But my level of skill here is high, and going to level one, level two, level three is complicated. You have a ladder to solve the problems quickly. That's the problem. Any platform, any vendor has the same problem. You need to go through levels until you find one guy who can solve your problem.

Which solution did I use previously and why did I switch?

I used a solution previously. I switched because I needed evolving technology. I needed to evolve to smart features.

The most important criteria when selecting a vendor is price. After that it's detection.

How was the initial setup?

For the first steps you have some help. At the beginning you have priority support, you have engineers. After that you pay.

It's complex because you need to evaluate a lot of things.

What other advice do I have?

I advise that you should plan your financial resources and plan the platform. Also, be sure to test the performance ability, as well as scalability. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user293913 - PeerSpot reviewer
IT Security and Compliance Officer at a energy/utilities company with 501-1,000 employees
Vendor
It gives us a greater visibility into potential data/network breach attempts with the monitoring and alerting capabilities.

What is most valuable?

  • Log correlation
  • Alerting

How has it helped my organization?

AccelOps gives us a greater visibility into potential data/network breach attempts with the monitoring and alerting capabilities.

What needs improvement?

Ease-of-use for end users that do not spend every day in the product.

Also, the presentation of historical and trending data in dashboards needs to be improved immensely. Something as simple as an RRDtool graphing mechanism on a dashboard would be a huge improvement to the product.

For how long have I used the solution?

I've used it for one and half years.

What was my experience with deployment of the solution?

Not that I recall, but its been over a year since deployment.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

It's high.

Technical Support:

Medium to high, some of the problems is just in the maturity of the product and how AccelOps develops this moving forward.

Which solution did I use previously and why did I switch?

Solarwinds, we assumed that AccelOps would be an easier product to manage moving forward and it was less expensive.

How was the initial setup?

I don't think it was complex.

What about the implementation team?

In-house with a little assistance from support.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user675411 - PeerSpot reviewer
Senior Technical Consultant at a integrator with 201-500 employees
Vendor
Configuration in initial setup is complex. Product's analytics provide log info letting you see threats.
Pros and Cons
  • "Analytics. It can provide log information from the device. With log information, I can see if there is a threat"
  • "If there is a configuration on the wrong side of the network or there are changes that result in harm to our IT infrastructure, the solution should immediately fix it."

How has it helped my organization?

From CMDB configuration monitoring, it can provide information changes.

What is most valuable?

Analytics. It can provide log information from the device. With log information, I can see if there is a threat

What needs improvement?

In the CMDB configuration monitoring. Example, if there is a configuration on the wrong side of the network or there are changes that result in harm to our IT infrastructure, the solution should immediately fix it.

What do I think about the stability of the solution?

Yes.

What do I think about the scalability of the solution?

Yes.

How are customer service and technical support?

Very good.

Which solution did I use previously and why did I switch?

FortiSIEM is better than previous products.

How was the initial setup?

Complex due to the configuration.

What's my experience with pricing, setup cost, and licensing?

Please be cheaper and more simplified.

Which other solutions did I evaluate?

Yes, but I cannot mention it because of privacy issues.

What other advice do I have?

Please do a PoC.

Disclosure: My company has a business relationship with this vendor other than being a customer: I'm Partner.
PeerSpot user
Security Team Leader at a tech services company with 11-50 employees
Reseller
Our customers have seen improvement in their connection with load balancing on both connections
Pros and Cons
  • "Some of our customers who use this solution have seen improvement in their connection with load balancing on both connections."
  • "Our customers are noticing configuration available in the GUI interface and I think that they should be equal."

What is our primary use case?

We are a system integrator and we resell this solution.

How has it helped my organization?

Some of our customers who use this solution have seen improvement in their connection with load balancing on both connections.  

What needs improvement?

Our customers are noticing configuration available in the GUI interface and I think that they should be equal.

What do I think about the stability of the solution?

Stability and scalability are perfect. 

How was the initial setup?

The initial setup wasn't complex. It took three days to deploy and we required two people for the deployment. 

What other advice do I have?

I would rate it a nine out of ten. The configuration should be equal with the GUI interface. 

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
PeerSpot user
ICT Architect at a insurance company with 51-200 employees
Real User
Never crashes but lacks integration with Fortinet products
Pros and Cons
  • "The most valuable feature is the anomaly-reporting alarms."
  • "Areas for improvement would be the ease of use and the integration with Fortinet's own products."

What is most valuable?

The most valuable feature is the anomaly-reporting alarms.

What needs improvement?

Areas for improvement would be the ease of use and the integration with Fortinet's own products.

For how long have I used the solution?

I've been using this solution for three years.

What do I think about the stability of the solution?

This is a very stable product - we have never had a crash with it. It does use a lot of resources, but this doesn't affect its performance.

What do I think about the scalability of the solution?

The scalability is ok and is improved by using Elasticsearch.

How are customer service and support?

The technical support has improved a lot and is now ok.

How was the initial setup?

The initial setup was a little difficult because no good guidelines were available. However, this has since been improved. It took around six months to finish a complete deployment.

What's my experience with pricing, setup cost, and licensing?

I have a five-year contract for this product, with no additional costs.

What other advice do I have?

I would give this solution a rating of seven out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
ICT Architect at a insurance company with 51-200 employees
Real User
CMDB database collects data from a lot of pre-configured devices
Pros and Cons
  • "The most valuable feature is the dashboard. CMDB database collects data from a lot of pre-configured devices."
  • "The performance can be improved. Sometimes it takes a long time to fetch data."

What is our primary use case?

We use the on-prem model of this solution. Our primary use case is for malware and behavior monitoring. We also use it to monitor system performance and user behavior. 

What is most valuable?

The most valuable feature is the dashboard. CMDB database collects data from a lot of pre-configured devices. 

What needs improvement?

The performance can be improved. Sometimes it takes a long time to fetch data. 

For how long have I used the solution?

I have been using this solution for one and a half years.

What do I think about the stability of the solution?

It is very stable. 

What do I think about the scalability of the solution?

Scalability is very good. We currently have 150 users using this solution. We don't have plans to increase usage at the moment. 

What about the implementation team?

We implemented through Fortinet professional services. We were one of the first customers to implement the new version and it was a bit complex. I believe it has become easier. Deployment took them only a few hours. It didn't take a long time. 

What other advice do I have?

I would rate it an eight out of ten. They should implement better behavior monitoring features to make it a perfect ten. It should also have better integration with their own products. They have a lot of interfaces for other products but it's not so easy to integrate their own devices. 

I would recommend this solution to someone considering it. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2024
Buyer's Guide
Download our free Fortinet FortiSIEM Report and get advice and tips from experienced pros sharing their opinions.