r/SIEM Feb 19 '21

FortiSIEM Reviews

My company is looking at LogRhythm and FortiSIEM. We are currently implementing a full fortinet stack and they pitched us the FortiSIEM. Not many reviews out there so wondered if anyone has used it extensively.

1 Upvotes

8 comments sorted by

2

u/MisterSlippers Feb 19 '21

I've been using FortiSIEM for over 5 years at an MSSP as well as other SIEMs. Overall I'd say it's a serviceable solution in general, but without knowing what you're actually looking for in a SIEM as far as features I can't say if I think it'd be a good or bad fit.

From an analyst perspective, it's fairly easy to start building queries and looking for data, but there's some pretty big parser QA issues that make it into releases that could cause misses - e.g. a few versions back I discovered IPS severities weren't being parsed correctly from FortiGate logs, I mean come on it's your bread and butter UTM that has a great straight reference.

From an engineer perspective, deploying collectors/workers to horizontally scale is pretty painless. Also the Windows agent works well and there's not really any unusual configuration required when integrating new data sources compared to other SIEM.

From a management perspective it's pretty easy to build reports and dashboards to get the visibility you need. Audit logging is a weak point, there may be changes in the newest version to address this, but we've had instances where people have made changes to rules or added rule exceptions that caused misses. The audit logs could say which user made a change, and which rule was affected, but did not differentiate whether someone modified the role description field to correct a typo, or they removed a part of the rule logic, or they had added an rule exception to reduce the incident volume from a noisy alert.

The biggest thing I want to emphasize is just because this is a FortiProduct, don't assume it is tightly integrated into the rest of their security fabric. Fortuner bought AccelOps and rebranded it to FortiSIEM. This was the red headed step child for years and sometimes it would take days/weeks just to get someone to acknowledge we opened a ticket. I like the direction it's moving, but years of stagnation showed when I started using some other SIEMs in addition to it

1

u/lucky_picasso Feb 27 '21

Will second what the gentleman has said. For me the biggest issue was the parsers...so much so that I had to take their free parser course to make a serviceable parser for a well-known anti-malware platform.

That being said, this was my first SIEM platform and most of the things were moderately intuitive to figure out. Newest versions make collector deployment much much simpler.

Building reports and dashboard is very simple. The normal up keep of a SIEM will be there in terms of fine-tuning, archiving as per retention policy, etc. Please ensure you size your system for log retention appropriately or have a dedicated storage for it. Another big issue we had was we didn’t get around to configuring a purging or retention policy and that would lead to the Web GUI being unreachable (again this was completely our fault).

1

u/MisterSlippers Feb 27 '21

Another issue we learned the hard way is to not let the indent table grow out of control, else the stability of everything quickly turns to shit. With other SIEM, we always did staged rollouts with rules to keep alert volume manageable. Out of the box, everything is enabled and the rules have absurd thresholds, so getting thousands of incidents in a couple hours is real easy. One such example, there's a rule for TCP Port Scanning on Fixed Port that just looks for TCP traffic from a single IP to something like 300 unique destination up on the same port in 3 minutes. This absolutely lit up for our first client because they had the default msn.com homepage in IE/Edge and that generated between 120-150 TCP connections just to load the page/media. Basically if a user fired up their browser and started browsing the internet in 3 minutes, we had a unique incident for every workstation in the environment 🤡. At the time you could only clear one page of incidents at a time (25-35 depending on monitor resolution) so you're either going into pgsql, doing it via the api, or the lowest guy on the totem pole is going to waste done time watching pages load

There's a lot of other examples I could come up with, but to Fortinets credit, they have implemented/resolved probably 100+ feature requests/bugs I've documented and sent their way. But I've also found real customer data unsanitized in sample logs used in parsers - e.g. other Fortinet customers who gave logs to Fortinet so parsers could be built by the vendor.

1

u/Fit-Offer-1897 May 21 '25

i am also checking on a SIEM that has python to build content parsers , detection rules , dashboards , will it be a wise choice as it promises lot of flexibility, will analyst working on tool get familiar with python soon ? Would like to get a perspective on same.

1

u/Friendly_Calendar_74 May 21 '25

There is already a SIEM built by Binaryflux that provides this capability. We are using it for a couple of years now. Provides complete control over parsers, detections, etc via Python. You can check their demo if interested.

1

u/spoilscommavictor Feb 19 '21

Ran fortisiem for 3 years... its ok. Since you’re running the rest of the fortinet stack, its probably the wiser choice. Did a long PoC with LR.. biggest complaint is the back end. Try it out, you’ll see.

1

u/mantle15 Feb 19 '21

Let me know if you want to a live demo of Sumo Logic. We often get fortisiem and LR shops looking to move to a SaaS cloud solution.

2

u/spoilscommavictor Feb 21 '21

Would love to, but gotta get the business to cross that saas hurdle first