We are creating our new dashboards and correlations as per our requirements with Fortinet FortiSIEM.
We have found the most important features in Fortinet FortiSIEM to be the correlation, file utility check, latest file, and hash changes. These features are important for us.
We expect the latest patch from Fortinet FortiSIEM to give the ability to work with signature files.
The patch management on the software needs to be better. We have not received frequent updates from their site. That's the major challenge for us. Going by the latest trends there are lots of cyber attacks happening in the entire world. All of the latest trends, patches, file updates, and hash updates should be released as soon as possible, whilst an attack is detected the patch has to be released on time.
I have been using Fortinet FortiSIEM for two and a half years.
It's a foolproof solution for our requirements, it is stable.
The solution is scalable. However, this depends on the license we purchase. Additionally, to scale the solution requires a large investment for computer hardware, such as SSD, memory, and CPUs.
We have approximately 25 security engineers using the solution and approximately 10,000 end users.
We do not have plans to increase the usage of the solution at this time.
I would rate the support of Fortinet FortiSIEM a four out of ten.
We previously were using the Juniper STRM, but Juniper STRM is currently not available. I think that their company was taken over by IBM QRadar, this is why we have gone with FortiSIEM.
The workload required for this software is a major challenge. It requires a huge workload in terms of CPU and memory. It requires a huge workload for the installation and for the integration with all the systems. The whole implementation took approximately six months.
We had help from the Fortinet team for the implementation team.
We have received a return on investment by using this solution.
The price of Fortinet FortiSIEM is a lot less when compared to other solutions.
My advice to others thinking about implementing this solution is if your organizational budget is low, then we go for Fortinet FortiSIEM. Otherwise, if we have enough budget, I would recommend IBM QRadar and or other solutions.
I rate Fortinet FortiSIEM a six out of ten.