Sign in Agent Mode
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Fortinet FortiSIEM Cloud

Fortinet Inc.

Reviews from AWS customer

0 AWS reviews
  • 5 star
    0
  • 4 star
    0
  • 3 star
    0
  • 2 star
    0
  • 1 star
    0

External reviews

60 reviews
from and

External reviews are not included in the AWS star rating for the product.


    Mohamed Fouad

Building a multi-customer SOC has become more efficient with reliable event correlation and strong licensing support

  • November 20, 2025
  • Review provided by PeerSpot

What is our primary use case?

My main use case for Fortinet FortiSIEM is building a SOC and serving as an event management platform for correlating events in my work.

I use Fortinet FortiSIEM for event correlation by building a SOC for many customers, allowing the SOC team to rely on SIEM technology to correlate and manage events from all security products.

What is most valuable?

The best features Fortinet FortiSIEM offers are reliability and scalability.

Reliability and scalability have helped me in my work, especially because the license for Fortinet FortiSIEM is excellent from a cost perspective, and we can add more collectors as we expand.

Fortinet FortiSIEM has positively impacted my organization by allowing us to manage our security and build our SOC.

What needs improvement?

Fortinet FortiSIEM is great overall. Performance could be enhanced, but I do not wish to elaborate on needed improvements.

For how long have I used the solution?

I have been using Fortinet FortiSIEM for five years.

What do I think about the stability of the solution?

Fortinet FortiSIEM is stable.

What do I think about the scalability of the solution?

Fortinet FortiSIEM's scalability is excellent, and it is also easy to configure, maintain, and operate.

How are customer service and support?

The customer support for Fortinet FortiSIEM is excellent. I have interacted with their support team, and Fortinet's support is known to be wonderful.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I previously used IBM QRadar as a different solution.

What was our ROI?

I have seen a return on investment that is excellent. The platform has resulted in time saved and reduces mean time to response, making it a great platform.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing for Fortinet FortiSIEM is wonderful, as it offers an excellent license compared to other vendors.

Which other solutions did I evaluate?

Before choosing Fortinet FortiSIEM, I evaluated IBM QRadar as another option.

What other advice do I have?

My advice for others looking into using Fortinet FortiSIEM is that it is better to use Fortinet FortiSIEM for building your SOC and maintaining your incident response at the SOC. I have provided this review with a rating of 10.


    reviewer2731089

Security tool facilitates efficient monitoring and policy customization

  • August 15, 2025
  • Review provided by PeerSpot

What is our primary use case?

I have a lot of experience working with solutions such as Fortinet FortiSIEM, FortiSOAR, and FortiGate. I have also worked with ImmuniWeb. However, I did not have the credentials or the software to work with ImmuniWeb, which is why I was searching for more information on the website to learn more about the tool.

In the company I work for, we have a partnership with Fortinet.

In my organization, I work on Fortinet FortiSIEM in the cloud.

What is most valuable?

Fortinet FortiSIEM is really user-friendly. You can filter easily, find rules, and even create new rules. I appreciate Fortinet FortiSIEM the most because it is easy to search, filter, make rules, and look for correlations and events.

For Fortinet FortiGate, it is easy to navigate through the tool itself, make policies, and look at events and logs. It is very easy to monitor on Fortinet FortiGate. I really appreciate it and believe anyone in the field can work with it easily.

For FortiSOAR, it is easy to work with playbooks and rules for approvals, and everything there is straightforward. Fortinet FortiSIEM pulls the events from FortiSOAR, processes them, and applies the playbooks. It is simple in its functions, has correlations, and offers everything needed.

I can find everything I need on Fortinet FortiSIEM. The filters, trends, and dashboard make it easy to use. The database, alerts, and customer service are excellent as well.

What needs improvement?

Regarding Fortinet FortiSIEM, I cannot identify any specific areas for improvement because I can find everything I need. For the time being, I cannot find a real point for improvement. Everything is working great on Fortinet FortiSIEM.

For how long have I used the solution?

I have experience with Fortinet FortiSIEM for almost six months.

How are customer service and support?

For Cortex XDR from Palo Alto, it rates 10 out of 10. Everything is excellent with XDR and the technical support is exceptional.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have worked with Splunk and QRadar SIEM tools, but I prefer Fortinet FortiSIEM the most.

What's my experience with pricing, setup cost, and licensing?

I am not familiar with the price and cost of Fortinet FortiSIEM. I cannot tell you if it is high, expensive, or low. However, I can say that it is cost-effective as it provides everything needed.

Which other solutions did I evaluate?

I do not have relevant experience with tools such as Acunetix, Synopsys, Invicti, Snyk, Prolexic, AWS Shield, or Global Accelerator.

What other advice do I have?

I wish to remain anonymous, with no names for my company or myself. I prefer written communication rather than voice-based.

Based on my experience, I would rate this solution 9 or 10 out of 10.


    SaurabhYadav5

Comprehensive monitoring boosts security, yet incident management features need expansion

  • May 02, 2025
  • Review provided by PeerSpot

What is our primary use case?

Our primary use case for Fortinet FortiSIEM is mostly in government offices. We fully rely on vendors for implementation, and we generally review and approve the recommendations made by the implementation partners.

What is most valuable?

I use Fortinet FortiSIEM for complete infrastructure monitoring for security events. It supports a number of compliance rules that cater to different requirements. I find the real-time monitoring and correlation capabilities effective for security alerts. Fortinet FortiSIEM provides pre-built rules, with more than three thousand rules supplied, eliminating the need to define them from scratch. These aspects make Fortinet FortiSIEM a valuable choice.

What needs improvement?

Fortinet FortiSIEM should broaden its remediation part to include more features for incident management. Currently, to manage repetitive incidents or for remediation, I need to use a separate software called FortiSOAR. Additionally, the search functionality in FortiAI should be improved to provide more precise results, making it easier for me to understand what actions need to be taken.

For how long have I used the solution?

I have used the solution for one and a half years.

What was my experience with deployment of the solution?

I haven't faced any issues with deploying Fortinet FortiSIEM. The main setup can be done in one hour, and I prefer the VMware installation which is provided with VMDK or similar files. Installing agents on endpoint machines is the main task.

What do I think about the stability of the solution?

Occasionally, some stability issues occur, but Fortinet's technical support team provides assistance. As I mentioned earlier, every software can have bugs, and Fortinet does respond to fix these bugs. I would rate the stability at around seven to eight on a scale of ten.

What do I think about the scalability of the solution?

Fortinet FortiSIEM is easy to scale. I would rate its scalability an eight on a scale of ten.

How are customer service and support?

Fortinet's customer support is okay, but not very good. They take some time to respond because they need logs and investigations, which delays the response time. I expect faster responses for the issues raised.

How would you rate customer service and support?

Negative

How was the initial setup?

The initial setup of Fortinet FortiSIEM is not complex. It is very easy, as the software comes with pre-built rules.

What about the implementation team?

The implementation partners provide recommendations, but they only cover what is required in the scope of work. In case of any challenges, Fortinet’s tech support assists.

What's my experience with pricing, setup cost, and licensing?

The pricing is reasonable, which is why it is preferred by government customers. Windows agent licenses cost around 3,000 Rupees per device per year.

Which other solutions did I evaluate?

Suppose I buy Splunk SIEM, I need to configure all the required rules. In contrast, Fortinet FortiSIEM comes with over three thousand pre-built rules.

What other advice do I have?

If planning to use Fortinet FortiSIEM, it is important to know that it provides pre-built rules, which is a significant advantage. It is suitable for medium to enterprise customers. Overall, I would rate Fortinet FortiSIEM seven out of ten.


    Oliver Jackson

Systems monitoring enhanced by firewall and intrusion detection features

  • December 18, 2024
  • Review provided by PeerSpot

What is our primary use case?

My primary use case for Fortinet FortiSIEM is systems monitoring and alerting. I use it for standard functions like log monitoring, incident detection, and notification.

My customers are mostly medium-sized enterprises ranging from engineering companies, mining companies, independent schools, and government departments to agencies.

What is most valuable?

Fortinet FortiSIEM is valuable mainly for its features around firewall monitoring, intrusion detection, and authentication. It provides extensive logging and record-keeping for internal networks, cloud applications, and services as well as perimeter physical network security. Compliance management capabilities, although limited, are utilized by mature customers for reporting.

What needs improvement?

The built-in APIs in Fortinet FortiSIEM are somewhat lacking and could be improved for better integration with external ITSM products. Improving software stability and reducing bugs will make it a better tool for future use. Enhancing the completeness of its APIs could aid in better external integrations.

For how long have I used the solution?

I have used Fortinet FortiSIEM for three and a half years to nearly four years.

What do I think about the stability of the solution?

The product has some instability and bugs, which are not service-stopping but may cause unusual errors and user interface issues. I regularly work with Fortinet support to address these issues.

What do I think about the scalability of the solution?

Fortinet FortiSIEM is highly scalable. I would rate its scalability nine out of ten.

How are customer service and support?

The customer support from Fortinet is good. There is a knowledgeable, though small, team of support engineers around the world. I have come to know them all by name.

How would you rate customer service and support?

Positive

How was the initial setup?

From a new user's perspective, setting up Fortinet FortiSIEM could be rated as a five or six out of ten. However, with my four years of experience, I would rate the setup an eight out of ten.

What was our ROI?

Many of my customers are happy and have provided positive reviews about their experiences. They continue to pay for services and see value in the investment.

What's my experience with pricing, setup cost, and licensing?

As a service, the cost is reasonable and affordable with scalable pricing based on the number of monitored devices. However, setting it up for oneself as an enterprise-licensed product can be quite expensive.

What other advice do I have?

If you want to set it up yourself, seek expert support before starting. If considering a service, contact Fortinet for a recommended service provider in the FortiSIEM space.

I'd rate the solution eight out of ten.


    Muhammad Tayyab

Maps threat vectors and IOCs on the MITRE framework to identify the kind and magnitude of a threat and the techniques used

  • November 19, 2024
  • Review provided by PeerSpot

What is our primary use case?

Mainly, we are configuring various correlation rules in FortiSIEM to detect various types of cyber threats and cybersecurity attacks, particularly brute force attacks, denial of service attacks, and distributed denial. We are using it to identify suspicious activities by internal staff as well as outsiders, for any type of intrusion.

What is most valuable?

The most fascinating aspect of FortiSIEM is its integration with the MITRE ATT&CK framework. It maps threat vectors and IOCs on the MITRE framework to identify the kind and magnitude of a threat and the techniques used. This allows us to take requisite measures using the SOAR solution or by involving our team of SOC analysts and incident responders.

What needs improvement?

FortiSIEM is a bit resource-hungry, so work should be done on hardware resource utilization to consume less hardware. Another major problem is its licensing model, which initially required separate licenses for devices, agents, and EPS.

Recently, they revised it to a subscription-based, all-inclusive license. There is also some latency observed in generating correlation alerts, which should be improved for quicker responses.

For how long have I used the solution?

We have been using it for almost one year.

What do I think about the stability of the solution?

FortiSIEM is a reliable product. Multiple times, the server abruptly shut down, but no critical or major issues were observed after power outages. It stabilizes itself in an appropriate time, so its uptime is good.

What do I think about the scalability of the solution?

FortiSIEM is a scalable model. At any point in time, when network devices increase or there is a change in the infrastructure, we can add more workers and collectors to expand our infrastructure setup.

How are customer service and support?

Technical support in my city, specifically in Islamabad or Rawalpindi, is decent. I would rate it seven out of ten.

Local tech support is available, however, for more critical or technical issues, we depend on the OEM directly, especially when it comes to on-prem solutions.

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial installation requires some tech knowledge. You should have prior understanding of modules, collectors, workers, supervisors, and databases. However, after installation, it's really easy to operate.

What's my experience with pricing, setup cost, and licensing?

Fortinet FortiSIEM is high-priced. Previously, its licensing model required separate licenses for devices, agents, and EPS, which was quite rigid. The revised model is subscription-based and more flexible.

Which other solutions did I evaluate?

Compared to FortiSIEM, LogRhythm is a good competitor. QRadar is also a nice product, working equally well in our region.

What other advice do I have?

I would rate FortiSIEM eight out of ten. It's a nice product and is used by major governmental infrastructures and organizations. I would definitely recommend it to other users.


    Vishwajeet Pandey

Efficient monitoring tool consolidating network events for streamlined management

  • October 24, 2024
  • Review provided by PeerSpot

What is our primary use case?

FortiSIEM is primarily used as a monitoring tool that can monitor all the incidents and events occurring in the network. The main concern of the customer is to view all the events and incidents on a single pane where everything can be managed.

How has it helped my organization?

FortiSIEM is very efficient and helps discover all the points of incidents, identifying users that create loopholes in the network and determining potential points of contact.

What is most valuable?

The most valuable feature is the ability to view all the network events on a single pane and find the point of contact or point of the incident. Along with FortiSIEM, a solution can be provided, which is a feature I admire.

What needs improvement?

There could be improvements like introducing some solutions directly into FortiSIEM to avoid the need for separately purchasing additional tools like FortiStore.

For how long have I used the solution?

I have approximately one year of experience working with FortiSIEM.

What do I think about the stability of the solution?

I rate the stability of the solution as nine out of ten.

What do I think about the scalability of the solution?

The scalability of the solution is rated eight out of ten.

How are customer service and support?

I rate the technical support provided by Fortinet as nine out of ten.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup can vary from being easy to moderate depending on the network size. If the network is small, it might be easy. That said, if it's semi-small or semi-large, it's a moderate setup.

What's my experience with pricing, setup cost, and licensing?

The pricing of FortiSIEM is moderate; it is neither very costly nor very cheap.

What other advice do I have?

I can recommend FortiSIEM, but it depends on customer needs, network size, and preferences. Customers can also consider replacing a physical SOC team with FortiSIEM.

I'd rate the solution eight out of ten.


    reviewer2535720

It offers a complete analysis of the environment, but it is expensive

  • August 28, 2024
  • Review provided by PeerSpot

What is our primary use case?

I use the solution in my company for our client, which is a big university in Tunisia, and they have many servers and virtual machines. The university has to prevent attacks by making sure that they can stop the attack at the beginning. Fortinet is good for knowing if any of the equipment in the network has been attacked like ransomware or something, and we can stop the attack and secure the network.

What is most valuable?

The tool's most valuable feature stems from the fact that I can see a complete analysis, like all the incidents that have happened, and it detects everything in real-time. It lets you know of the attack in real-time. The tool sends alerts and reports, so I think it is a useful tool.

What needs improvement?

There is a port in Fortinet FortiSIEM. If something happens, you have to enter events and create a rule to stop the attack, which I think needs to be made automatic. If any incident occurs, I hope that Fortinet FortiSIEM does the work automatically without the intervention of a human or an IT admin.

I don't want to create a rule to stop an attack. Lately, many people have been trying to access the VPN, and they are not even registered with our firewall. The team detects issues but doesn't do anything. I have to create a rule to include the addresses and details of the people who want to access the VPN in the block list, but I want the tool to do all this without me.

For how long have I used the solution?

I have been using Fortinet FortiSIEM for two months. My company has a partnership with the solution.

What do I think about the stability of the solution?

It is a stable solution.

What do I think about the scalability of the solution?

The tool is scalable enough to do what you really want.

My clients run big businesses.

How are customer service and support?

The solution's technical support didn't help our company a lot. When it came to Fortinet FortiSIEM, we added the devices, and started making rules, but when we asked a question to the tool's support team, it took them a long time to answer. I rate the technical support a five out of ten.

How would you rate customer service and support?

Neutral

How was the initial setup?

At the beginning the product's initial setup phase was complex. Lately, since I have started to understand the tool, the setup phase has become easy.

The solution is deployed on an on-premises model with VMs in a local data center.

The solution can be deployed in four days. One day is for installing the VMs, one day is for understanding the tool's dashboard and its rules, one day is for installing the agents and adding the equipment, and one day is for seeing what the clients want exactly.

What's my experience with pricing, setup cost, and licensing?

The tool is really expensive. For what the tool does for our team, the price is fair.

What other advice do I have?

As my company did not fully complete everything, the installation is not stable 100 percent.

In terms of Fortinet FortiSIEM's uptime and system stability, the tool can do detection in real-time. I think it is available for users all the time.

Those who have many servers and equipment can use SIEM so they can manage. It helps a person to see what equipment has incidents and how to prevent an attack before it happens. You can't manage much equipment, like 15 VMs or servers, by yourself. You need solutions to do that and give you alerts if anything happens.

As the product is not automated enough, I rate the tool a seven out of ten.


    LENIN RAMIREZ

Is used to set up rules and conduct threat hunting but has a limited layout

  • August 23, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use this technology to configure and setup rules and conduct threat hunting.

How has it helped my organization?

Connecting all supported security technologies, such as firewalls from Palo Alto, Fortinet, and Check Point, is crucial. The platform needs to recognize logs coming from sources like Syslog. You might integrate an IPS or WAF for use cases like phishing. Whether on-premise or in the cloud, AD is especially important for providing context and supporting specific use cases. If FortiSIEM doesn't natively support a particular technology or cannot parse certain security logs, you can configure a custom parser to interpret those logs effectively.

What is most valuable?

It is used in analytics, providing powerful tools to obtain specific information. For instance, if you detect a potential OS DDoS attack, you can quickly search for detailed information about that threat. With features like threat hunting, you can query specific IP addresses and access extensive data.

Additionally, FortiSIEM allows you to match IPs with threat intelligence feeds from sources like Kaspersky or Anomali, adding valuable context. The platform also simplifies rule configuration, making setting up rules for specific use cases easy and highlighting its effectiveness as a robust security solution.

What needs improvement?

When an alert triggers in Fortinet FortiSIEM, the layout or format can feel limited; the template you configure for alerts offers only a few specific fields, which can be restrictive. It would be much better if the technology supported more fields or allowed for greater customization, making it more versatile for managers to tailor alerts according to their specific use cases. This limitation is a weakness of the platform.

For how long have I used the solution?

I have been using Fortinet FortiSIEM as a partner for two years.

What do I think about the scalability of the solution?

600 users are using this solution.

To effectively plan for the future, it's important to anticipate how much the organization will grow. Considering Fortinet's MSSP model, you need to estimate how many clients you'll acquire and how much your client base might expand. For a single organization, it's crucial to understand how many users you'll be adding during that period to ensure the system can scale accordingly.

How are customer service and support?

Support responds very slowly.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have used ArcSight. Fortinet stands out because it supports a broader range of technologies, allowing for greater integration within a system. Another key advantage is its robust analytics, making it easier to obtain specific information consistently.

How was the initial setup?

The initial setup is easy. If you want to deploy FortiSIEM on-premise, you need to purchase a specific appliance or install it on your hardware. I have deployed FortiSIEM both on-premise and in the cloud, managing both environments effectively.

Deployment depends on the architecture since FortiSIEM uses various components, such as the supervisor, event collector, and worker. It can be set up in just one day if you're deploying it as an all-in-one solution.

What about the implementation team?

I did the deployment alone.

What's my experience with pricing, setup cost, and licensing?

Pricing is moderate.

What other advice do I have?

Maintenance depends on the number of log sources configured and the overall architecture. The system's load must be considered to monitor all components and handle upgrades or fix specific features. Managing the system typically requires just a couple of people for an all-in-one deployment with around ten to twenty log sources.

Overall, I rate the solution a seven out of ten.


    Nikesh Kakshapti

Has auto-discovery feature and helps with centralized log collection

  • August 19, 2024
  • Review provided by PeerSpot

What is our primary use case?

The primary use case of FortiSIEM for my client is to provide comprehensive security information and event management (SIEM) capabilities. It is used to monitor, detect, and respond to security incidents across the client's network by aggregating and analyzing logs, events, and other data from various sources. FortiSIEM enables real-time threat detection, compliance reporting, and overall visibility into the security posture, helping to identify potential risks and take proactive measures to protect the organization's infrastructure.

How has it helped my organization?

Fortinet FortiSIEM has positively impacted my client's organization by enhancing their ability to monitor security incidents in real time. The solution has provided comprehensive visibility into the network, allowing for quicker identification of potential threats. FortiSIEM's integration with various systems to collect different types of logs and its ability to correlate data from multiple sources have been particularly valuable in reducing the time spent on manual analysis and increasing overall security efficiency.

What is most valuable?

The most valuable feature is auto-discovery. When you send logs from various device to FortiSIEM it automatically detects and maps all devices, across the network, providing a comprehensive and up-to-date inventory of the IT environment

It's agent-based UEBA enhances security monitoring by utilizing agents installed on endpoints to collect detailed user activity data.It offers deeper insights into user behaviors, improving anomaly detection accuracy.

It's out-of-the-box compliance reporting features significantly ease the burden of regulatory compliance for organizations by offering pre-built report templates aligned with industry standards. Automated report generation minimizes manual effort and reduces the risk of errors, while customizable reporting allows organizations to tailor reports to specific needs.

What needs improvement?

One area where FortiSIEM could improve is in its custom normalizer/parser capabilities. While FortiSIEM offers powerful event correlation and log analysis features, creating and customizing normalizers can be complex and time-consuming.

Improving the user interface for building custom normalizers, along with providing more intuitive tools or templates, would make it easier for security teams to tailor the solution to specific needs. Enhancements in this area would enable quicker adaptation to unique log formats and data sources, allowing for more accurate event parsing and better overall performance in diverse environments.

Additionally, the search functionality could be less confusing. Streamlining the search experience and providing clearer guidance or examples would help users quickly find the information they need, ultimately improving the overall usability of the platform. These enhancements would facilitate quicker adaptation to unique log formats and more efficient event analysis, leading to better performance in diverse environments.

For how long have I used the solution?

I have used the solution for two years.

What do I think about the stability of the solution?

I rate the solution's stability a seven point five out of ten.

What do I think about the scalability of the solution?

Regarding scalability, it's better for vertical and horizontal scale-up, but expanding log sources isn't very easy due to the licensing model.

How are customer service and support?

The support team was great, technically proficient, and helped with numerous bugs.

How would you rate customer service and support?

Positive

How was the initial setup?

The installation and setup can be tough, requiring planning for hardware segregation and log volume. However, the installation isn't too difficult if you have clear requirements.

What other advice do I have?

For those interested in using Fortinet FortiSIEM, I'd advise planning your hardware specifications and considering backup and archives to prevent log loss. It's worth the money for what they've developed.

It's difficult for beginners to learn, mainly because of Fortinet FortiSIEM's specific queries and the lack of a user-friendly environment. Understanding these queries to find your desired logs can be challenging for newcomers.

I'd rate Fortinet FortiSIEM an eight out of ten because it's powerful and simple.


    Johan Ortiz

Audits servers, handles vulnerability detection and correlates traffic

  • August 14, 2024
  • Review provided by PeerSpot

What is our primary use case?

Fortinet FortiSIEM is used to audit my servers and communications. It effectively handles vulnerability detection and correlates traffic to identify security issues or anomalies. It is also used to correlate my logs, which helps detect outliers and identify unusual events in my network.

What is most valuable?

It detects new technologies, vulnerabilities, and emerging threats on the internet.

For how long have I used the solution?

I have been using Fortinet FortiSIEM for four years.

What do I think about the scalability of the solution?

500 users are using this solution.

How are customer service and support?

The product could benefit from more local support. There is an opportunity to improve the support for products like Deepgram and FortiSIEM.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

The deployment of the platform took some time to set up and configure. I have experience using SolarWinds and its tools.

How was the initial setup?

The initial setup is very easy and takes four months to complete. They need to focus on this because the provider did much of the configuration rather than them doing it directly. The support we receive helps us improve in comparison to using this platform alone.

I rate the initial setup an eight out of ten, where one is difficult, and ten is easy.

What about the implementation team?

Our provider does the deployment and maintenance.

What was our ROI?


What's my experience with pricing, setup cost, and licensing?

It has a good price and is more competitive than the others.

What other advice do I have?

If the protection and monitoring make my network safer by detecting outliers and events, I can report these findings to my manager. They need to be aware of live events affecting the company.

Overall, I rate the solution an eight out of ten.