To FortiSIEM or Not
Updated November 26, 2018

To FortiSIEM or Not

Eric V. Zarghami | TrustRadius Reviewer
Score 6 out of 10
Vetted Review
Verified User

Overall Satisfaction with FortiSIEM

As the name implies it's a SIEM solution which aggregates all the system generated logs into a single pane of view combined with some analytics resulting in actionable intelligence. By nature, it'll make it easier for the security team to stay on top of the important incidents that are reported by the information systems that support an organization. This can be viewed as a good investment for any company who has to work with fewer human resources due to financial constraints.

  • Log aggregation and analytics
  • CMDB
  • Device inventory and remote management .
  • It can be used by Managed Security Providers who have multiple customers as it offers multi organization support .
  • Non-intuitive/unattractive user interface
  • Too many features that will usually remain unused
  • Very crowded (too many icons) portal
  • The reporting feature is confusing, e.g. you have to click on the "refresh" button to get the result of your inquiry. The report generation process can be much easier, as the user interaction is not pleasant.
  • Other SIEM solutions were cost prohibitive at the time of purchase (2016).
  • Just like any other SIEM, it helped draw a better picture of our current security posture.
If budget is an issue then Fortisiem fits well, as it's more than a typical SIEM solution. It can integrate with environmental monitoring systems, UPS HVAC etc. It can be used as the CMDB solution etc. If fine-tuned and looked after it can actually bring a lot of value for less.

FortiSIEM Feature Ratings

Centralized event and log data collection
6
Correlation
7
Event and log normalization/management
6
Deployment flexibility
3
Integration with Identity and Access Management Tools
Not Rated
Custom dashboards and workspaces
4
Host and network-based intrusion detection
6