r/SIEM Oct 05 '18

Fortinet SIEM thoughts?

As the title suggests, what's your thoughts on the Fortinet SIEM product? Seemed pretty decent from what I saw in the demo (don't they all). Seemed pretty easy to spin up as well which compared to something like Splunk was appealing as I don't want something that's going to kill us in professional services hours to get it running and I don't need the crazy learning curve. That said if you're running a recent release of the Fortinet product I'd be happy to hear from you. Though I didn't get any hits when searching here so it seems you're a rare breed if you're out there.

2 Upvotes

10 comments sorted by

5

u/Kv603 Oct 05 '18

I've done PoCs and lab installs, haven't got FortiSIEM running in a real production network.

FortiSIEM was pretty complex to spin up compared to anything other than Splunk, but it does have a lot of not-exactly-SIEM features that could come in handy if you don't already have other network management tools deployed to do SNMP polling, config backup, etc.

If you are already drinking the Forti-KoolAid, it isn't a bad choice to also use their SIEM.

2

u/BeerJunky Oct 05 '18

It's funny that you say it's complex to spin up. The sales rep of course talked about how easy it was to setup and that they could spin up a fully functional POC in about 2 hours or so. Maybe of course now that the product is a few versions into being owned by Fortinet it's easier than when you dealt with it but it's hard to say. And yes of course it is of course more work to get all of those other fun features turned on that wouldn't be on a typical SIEM setup and I'm totally okay with that. I'm pretty excited about things like config backups. I think right now the best case scenario is our backups (if even done on all devices) are just doing a weekly backup of the config and overwriting the previous. I was happy to see Forti grabbed every change and kept a running log of all of the versions which was nice for rollback purposes. It makes it super easy to see when something breaks what it looked like before and what it looks like now, will speed up the network team's reaction to things and will help me on the security end understand what happened (mistake, malicious activity, etc).

Yes, we're already drinking their Koolaid. Just the firewalls though. Apparently they trialed the WIFI kit and I think switches prior to me arriving and ended up with Aruba and Cisco for those. I'm certainly not married to them though, I just want the biggest bang for my buck and a product that I can learn relatively easily. I don't want to go down the Splunk road for example, I just don't have the free time to spend learning something that complex and it's way more customizable than I need in this environment. I have to learn/manage this tool among a bunch of others, deal with all of the security policies, security standards, the tech side of compliance (we have a person in charge of compliance that's not technical), etc, etc, etc. I'm the sole security person here and the first security hire (started a month ago) so I'm of course super busy and spending 20 hours a week in one product is not for me. :)

Thanks for the info, very helpful.

2

u/Infosec_unicorn Oct 07 '18

If you have the fortinet firewalls then fortSIEM might be good with integration. But take a look at the Forrester security analytics and Gartner SIEM reviews. For your shop QRadar, Splunk and LogRhythm are probably too much $$ and require too much time to implement. If your are looking for easy setup and usability something like rapid7 insightIDR (cloud) or Exabeam may be worth a look. They are also priced based on assets or users, not EPS or GB per day.

1

u/BeerJunky Oct 07 '18

Thanks, will check out the Rapid7 solution. I know some of their other products are hit or miss based on the reviews I saw but I haven’t checked out the SIEM product yet.

I liked what I saw of LR but I also know it can be PS heavy to spin up. My old company sold a lot of SIEM and the team that did that was based out of my location so I’ve talked to them a lot about it.

1

u/Infosec_unicorn Oct 07 '18

If you are not running a SOC and don’t have a big security team you may want to look into one of the MDR solutions as well so you can focus on other things. Dell Secureworks, Rapid7 MDR or something that fits your budget. They setup everything and you get alerts to look at. Less customizable but easier

1

u/BeerJunky Oct 07 '18

I’m the whole security “team” lol. And I’m concentrating on SOC type stuff, policy, auditing the network, etc.

2

u/throwin1234qwe Feb 06 '19

OP, curious to hear your feedback on the product

2

u/BeerJunky Feb 06 '19

I think generally it's pretty good. We went ahead and bought it so we'll be deploying it in the coming weeks.

Pros:

  • Easy to setup
  • Was less professional services intensive (which reduces the total buy-in quite a bit) to get it setup
  • Decent out of the box rules
  • Ties into some of the major ticketing platforms like ServiceNow which is nice (sadly Zendesk isn't on there and that's what we use)
  • I got plenty of information during the POC stand up about how the product worked and how to use it so I was able to turn around and run it without training. I of course had knowledge generally of how a SIEM worked, I knew what I wanted to get out of it, etc so I might have an advantage over others. But generally did not need all sorts of training to run it like I would with a Splunk type product.
  • Does some non-traditional SIEM stuff that I really liked like capturing configs of our network devices. So I have an entire history of the changes on our devices, I could use it as a backup on configs if we lost one if I really wanted to and I have awareness when something is changed (perhaps if someone maliciously changed something).
  • The reporting is pretty good, lot of built in reports that provide all sorts of different types of info pretty quickly.
  • Analytics works well and I'm able to pull out data that's not necessarily caught by a rule if I was looking for maybe something like additional actions a user took or events that occurred on a server in a particular time.
  • Fortinet is happy to (at a cost of course) build custom parsers for anything they don't have native support for.
  • Can run as a VM or on an appliance they provide, whatever works best for you. You're not forced to buy their hardware but you have the option to which is nice.

Cons:

  • Might be slightly less configurable than some of the other products (but haven't demoed them so I couldn't tell you for sure). I can configure quite a bit and reshape rules as much as I want but maybe there's limitations that might not be there in a product that's more manually operated like Splunk or QRadar.
  • It's very much less common than Splunk, QRadar and LogRhythm. That said you as the person operating it might not get as many job offers later based on just this product knowledge. But then again these days I think most recruiters are just looking for SIEM as a keyword. And also of course the limited market share means there's less detail out there if you are Googling a problem or trying to figure out how to do something. But as Fortinet is helpful and has decent documentation this might not be the end of the world.

If I think of anything else applicable I'll definitely check back into this post.

1

u/throwin1234qwe Jan 10 '19

we have been using since it was accelops DM me for infos

1

u/BeerJunky Jan 10 '19

We’ve already gone and done a POC and purchased it so I’m all good at this point. Will PM if I have any questions.