FortiSIEM

FortiSIEM

Fortinet
+
+

Related Products

  • ManageEngine Log360
    190 Ratings
    Visit Website
  • ManageEngine EventLog Analyzer
    211 Ratings
    Visit Website
  • Graylog
    438 Ratings
    Visit Website
  • Blumira
    150 Ratings
    Visit Website
  • Orca Security
    606 Ratings
    Visit Website
  • ManageEngine ADAudit Plus
    614 Ratings
    Visit Website
  • Daylight
    11 Ratings
    Visit Website
  • Overmonitor
    8 Ratings
    Visit Website
  • ManageEngine Endpoint Central
    3,242 Ratings
    Visit Website
  • ESET PROTECT Advanced
    2,303 Ratings
    Visit Website

About

Powerful Security Information and Event Management (SIEM). Cyberattacks are a 24/7 reality. The complexity and growth of the enterprise estate – Infrastructure, Applications, VM’s, Cloud, Endpoints and IoT means the attack surface grows exponentially. Coupled with a skills shortage, and resource constraints, security becomes everybody’s problem but visibility, event correlation and remediation are other people’s responsibility. Effective security requires visibility – all the devices, all the infrastructure in realtime – but also with context – what devices represent a threat, what is their capability so you manage the threat the business faces, not the noise multiple security tools create. Security management only gets more complex. Endpoints, IoT, Infrastructure, Security Tools, Applications, VM’s and Cloud – the number of things you need to secure and monitor grows constantly.

About

Get a simple and fast security analytics implementation, along with a user-friendly interface that can be integrated with an entire IT infrastructure with LogPoint. LogPoint’s modern SIEM with UEBA provides advanced analytics and ML-driven automation capabilities that enable their customers to securely build-, manage, and effectively transform their businesses.They have a flat licensing model, based on nodes rather than data volume. This helps to reduce the cost of deploying a SIEM solution on-premise, in the cloud or even as an MSSP. The solution integrates easily with all devices in your network, giving a holistic and correlated overview of events in your IT infrastructure. LogPoint’s Modern SIEM solution translates all data into one common language, making it possible to compare events across all systems. Having a common language makes it both very easy and efficient to search, analyze and report on data.

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Audience

IT teams and professionals seeking a solution to improve their security operations

Audience

IT security teams searching for a powerful SIEM solution

Support

Phone Support
24/7 Live Support
Online

Support

Phone Support
24/7 Live Support
Online

API

Offers API

API

Offers API

Screenshots and Videos

Screenshots and Videos

Pricing

No information available.
Free Version
Free Trial

Pricing

No information available.
Free Version
Free Trial

Reviews/Ratings

Overall 5.0 / 5
ease 4.5 / 5
features 5.0 / 5
design 5.0 / 5
support 4.8 / 5

Reviews/Ratings

Overall 5.0 / 5
ease 5.0 / 5
features 4.0 / 5
design 5.0 / 5
support 5.0 / 5

Pros & Cons from Real Users

Pros

  • FortiSIEM includes automated workflows and incident response playbooks, reducing manual intervention and speeding up the remediation process. It can automatically trigger responses, such as blocking malicious IP addresses or isolating compromised endpoints, to mitigate risks without delay. FortiSIEM is designed with scalability in mind, making it suitable for large, geographically dispersed organizations. FortiSIEM distributed architecture allows it to handle a high volume of log data across different locations, ensuring that security data from remote offices or cloud environments can be collected, analyzed, and correlated without performance degradation.
  • FortiSIEM has native integration with other Fortinet security solutions, like FortiGate firewalls, FortiAnalyzer, and FortiClient. Integration enables enhanced visibility and a more cohesive security strategy across the entire network infrastructure, simplifying management and reducing the need for third-party integrations. FortiSIEM uses AI and machine learning to detect patterns in large volumes of security data. This proactive approach helps identify advanced persistent threats, zero-day attacks, and other sophisticated attack methods that might evade traditional rule-based systems.
  • FortiSIEM aggregates logs and events from multiple devices into a single dashboard, providing visibility across an organization’s infrastructure. It simplifies monitoring and managing network performance and security incidents, making it particularly useful for geographically distributed networks It excels in correlating events and identifying threats by leveraging advanced analytics, enabling proactive incident response. The user-friendly interface supports creating custom use cases and generating actionable insights The platform offers pre-defined reports for standards like HIPAA, SOX, and GDPR, making it a strong choice for organizations with stringent compliance needs​ By centralizing device management, FortiSIEM reduces operational costs related to staffing and travel, particularly for large organizations managing multiple locations Users often report difficulties in building custom reports and parsing rules, along with inconsistent support services, which can delay issue resolution
  • FortiSIEM provides a unified view of security events and compliance status across the entire IT infrastructure, offering deep insights into network, application, and device activities. The platform leverages advanced analytics and machine learning to detect and respond to security threats in real-time, enhancing proactive defense measures. The platform facilitates compliance with regulatory requirements through automated reporting and audit trails, reducing the complexity of compliance management. Fortinet provides robust support services and resources, including training programs and documentation, to assist organizations in maximizing the effectiveness of FortiSIEM implementation and operation. It integrates seamlessly with Fortinet's ecosystem of security products, consolidating security operations and optimizing synergy between different security solutions.

Cons

  • FortiSIEM provides a comprehensive set of features, it can be difficult to set up, especially for organizations without prior experience with SIEM solutions. The initial configuration, including integrations with Fortinet and third-party systems, may require significant expertise and time investment. For organizations with limited SIEM experience, the platform might feel overwhelming during the initial stages.
  • FortiSIEM supports integration with many third-party products, the integration may not always be as seamless or as deep as it is with Fortinet’s own ecosystem. Custom integrations or connectors for non-Fortinet products can require more effort and troubleshooting. FortiSIEM dashboard and interface are packed with detailed information and features which while powerful, may be difficult for new users to navigate quickly.
  • Setting up FortiSIEM can be time-consuming and challenging, especially for organizations integrating it into heterogeneous environments. Configuring devices to send logs and correlating data requires expertise and effort, which may overwhelm small teams​ FortiSIEM is most effective within the Fortinet ecosystem. Its integration with third-party technologies can be limited, posing difficulties in connecting diverse network infrastructure products. This can hinder organizations with mixed-vendor environments
  • Depending on the scale of deployment and configuration, FortiSIEM may consume considerable system resources, potentially impacting overall network performance. Regular updates and maintenance are essential for optimal performance of FortiSIEM, requiring dedicated resources and planning to ensure continuous security and operational efficiency.

Pros & Cons from Real Users

Pros

  • Ease of use and easy installation and customisation, no Linux or Unix knowhow needed, Excellent Support that also helps with how to questions, Supported Normalization of hundreds of log sources. Non programming SOAR with easy to use graphical workbook editor & very nice case management, Predefined and supported collectors and fetchers, Dashboards, Reports, Alert Rules etc.

Cons

  • If we must find something, user administration and rule based access is not always 100% transparent and might lead to duplicates.

Training

Documentation
Webinars
Live Online
In Person

Training

Documentation
Webinars
Live Online
In Person

Company Information

Fortinet
Founded: 2000
United States
www.fortinet.com/products/siem/fortisiem

Company Information

LogPoint
Founded: 2001
Denmark
www.logpoint.com

Alternatives

Alternatives

FortiAnalyzer

FortiAnalyzer

Fortinet
FortiSOAR

FortiSOAR

Fortinet
EventSentry

EventSentry

NETIKUS.NET ltd
Juniper Secure Analytics

Juniper Secure Analytics

Juniper Networks

Categories

Categories

SIEM Features

Application Security
Behavioral Analytics
Compliance Reporting
Endpoint Management
File Integrity Monitoring
Forensic Analysis
Log Management
Network Monitoring
Real Time Monitoring
Threat Intelligence
User Activity Monitoring

SIEM Features

Application Security
Behavioral Analytics
Compliance Reporting
Endpoint Management
File Integrity Monitoring
Forensic Analysis
Log Management
Network Monitoring
Real Time Monitoring
Threat Intelligence
User Activity Monitoring

Application Performance Monitoring (APM) Features

Baseline Manager
Diagnostic Tools
Full Transaction Diagnostics
Performance Control
Resource Management
Root-Cause Diagnosis
Server Performance
Trace Individual Transactions

Computer Security Features

Anti Spam
Antivirus
Audit Trail
Compliance Management
Database Security Audit
File Access Control
Financial Data Protection
Maintenance Scheduling
Real Time Monitoring
Security Event Log
Virus Definition Update
Vulnerability Protection

Integrations

Chronicle SOAR
Airlock
Azure Marketplace
BackBox
FortiADC
GoSecure
NXLog
OctoXLabs
Recorded Future
SOC Prime Platform
Safetica
Splunk SOAR
Swimlane
Tenable One
ThreatConnect Risk Quantifier (RQ)
Wraith

Integrations

Chronicle SOAR
Airlock
Azure Marketplace
BackBox
FortiADC
GoSecure
NXLog
OctoXLabs
Recorded Future
SOC Prime Platform
Safetica
Splunk SOAR
Swimlane
Tenable One
ThreatConnect Risk Quantifier (RQ)
Wraith
Claim FortiSIEM and update features and information
Claim FortiSIEM and update features and information
Claim LogPoint and update features and information
Claim LogPoint and update features and information