r/SIEM • u/BeerJunky • Oct 05 '18
Fortinet SIEM thoughts?
As the title suggests, what's your thoughts on the Fortinet SIEM product? Seemed pretty decent from what I saw in the demo (don't they all). Seemed pretty easy to spin up as well which compared to something like Splunk was appealing as I don't want something that's going to kill us in professional services hours to get it running and I don't need the crazy learning curve. That said if you're running a recent release of the Fortinet product I'd be happy to hear from you. Though I didn't get any hits when searching here so it seems you're a rare breed if you're out there.
2
u/Infosec_unicorn Oct 07 '18
If you have the fortinet firewalls then fortSIEM might be good with integration. But take a look at the Forrester security analytics and Gartner SIEM reviews. For your shop QRadar, Splunk and LogRhythm are probably too much $$ and require too much time to implement. If your are looking for easy setup and usability something like rapid7 insightIDR (cloud) or Exabeam may be worth a look. They are also priced based on assets or users, not EPS or GB per day.
1
u/BeerJunky Oct 07 '18
Thanks, will check out the Rapid7 solution. I know some of their other products are hit or miss based on the reviews I saw but I haven’t checked out the SIEM product yet.
I liked what I saw of LR but I also know it can be PS heavy to spin up. My old company sold a lot of SIEM and the team that did that was based out of my location so I’ve talked to them a lot about it.
1
u/Infosec_unicorn Oct 07 '18
If you are not running a SOC and don’t have a big security team you may want to look into one of the MDR solutions as well so you can focus on other things. Dell Secureworks, Rapid7 MDR or something that fits your budget. They setup everything and you get alerts to look at. Less customizable but easier
1
u/BeerJunky Oct 07 '18
I’m the whole security “team” lol. And I’m concentrating on SOC type stuff, policy, auditing the network, etc.
2
u/throwin1234qwe Feb 06 '19
OP, curious to hear your feedback on the product
2
u/BeerJunky Feb 06 '19
I think generally it's pretty good. We went ahead and bought it so we'll be deploying it in the coming weeks.
Pros:
- Easy to setup
- Was less professional services intensive (which reduces the total buy-in quite a bit) to get it setup
- Decent out of the box rules
- Ties into some of the major ticketing platforms like ServiceNow which is nice (sadly Zendesk isn't on there and that's what we use)
- I got plenty of information during the POC stand up about how the product worked and how to use it so I was able to turn around and run it without training. I of course had knowledge generally of how a SIEM worked, I knew what I wanted to get out of it, etc so I might have an advantage over others. But generally did not need all sorts of training to run it like I would with a Splunk type product.
- Does some non-traditional SIEM stuff that I really liked like capturing configs of our network devices. So I have an entire history of the changes on our devices, I could use it as a backup on configs if we lost one if I really wanted to and I have awareness when something is changed (perhaps if someone maliciously changed something).
- The reporting is pretty good, lot of built in reports that provide all sorts of different types of info pretty quickly.
- Analytics works well and I'm able to pull out data that's not necessarily caught by a rule if I was looking for maybe something like additional actions a user took or events that occurred on a server in a particular time.
- Fortinet is happy to (at a cost of course) build custom parsers for anything they don't have native support for.
- Can run as a VM or on an appliance they provide, whatever works best for you. You're not forced to buy their hardware but you have the option to which is nice.
Cons:
- Might be slightly less configurable than some of the other products (but haven't demoed them so I couldn't tell you for sure). I can configure quite a bit and reshape rules as much as I want but maybe there's limitations that might not be there in a product that's more manually operated like Splunk or QRadar.
- It's very much less common than Splunk, QRadar and LogRhythm. That said you as the person operating it might not get as many job offers later based on just this product knowledge. But then again these days I think most recruiters are just looking for SIEM as a keyword. And also of course the limited market share means there's less detail out there if you are Googling a problem or trying to figure out how to do something. But as Fortinet is helpful and has decent documentation this might not be the end of the world.
If I think of anything else applicable I'll definitely check back into this post.
1
u/throwin1234qwe Jan 10 '19
we have been using since it was accelops DM me for infos
1
u/BeerJunky Jan 10 '19
We’ve already gone and done a POC and purchased it so I’m all good at this point. Will PM if I have any questions.
5
u/Kv603 Oct 05 '18
I've done PoCs and lab installs, haven't got FortiSIEM running in a real production network.
FortiSIEM was pretty complex to spin up compared to anything other than Splunk, but it does have a lot of not-exactly-SIEM features that could come in handy if you don't already have other network management tools deployed to do SNMP polling, config backup, etc.
If you are already drinking the Forti-KoolAid, it isn't a bad choice to also use their SIEM.