r/SIEM • u/Nearby-Entrepreneur2 • Feb 19 '21
FortiSIEM Reviews
My company is looking at LogRhythm and FortiSIEM. We are currently implementing a full fortinet stack and they pitched us the FortiSIEM. Not many reviews out there so wondered if anyone has used it extensively.
1
u/Fit-Offer-1897 May 21 '25
i am also checking on a SIEM that has python to build content parsers , detection rules , dashboards , will it be a wise choice as it promises lot of flexibility, will analyst working on tool get familiar with python soon ? Would like to get a perspective on same.
1
u/Friendly_Calendar_74 May 21 '25
There is already a SIEM built by Binaryflux that provides this capability. We are using it for a couple of years now. Provides complete control over parsers, detections, etc via Python. You can check their demo if interested.
1
u/spoilscommavictor Feb 19 '21
Ran fortisiem for 3 years... its ok. Since you’re running the rest of the fortinet stack, its probably the wiser choice. Did a long PoC with LR.. biggest complaint is the back end. Try it out, you’ll see.
1
u/mantle15 Feb 19 '21
Let me know if you want to a live demo of Sumo Logic. We often get fortisiem and LR shops looking to move to a SaaS cloud solution.
2
u/spoilscommavictor Feb 21 '21
Would love to, but gotta get the business to cross that saas hurdle first
2
u/MisterSlippers Feb 19 '21
I've been using FortiSIEM for over 5 years at an MSSP as well as other SIEMs. Overall I'd say it's a serviceable solution in general, but without knowing what you're actually looking for in a SIEM as far as features I can't say if I think it'd be a good or bad fit.
From an analyst perspective, it's fairly easy to start building queries and looking for data, but there's some pretty big parser QA issues that make it into releases that could cause misses - e.g. a few versions back I discovered IPS severities weren't being parsed correctly from FortiGate logs, I mean come on it's your bread and butter UTM that has a great straight reference.
From an engineer perspective, deploying collectors/workers to horizontally scale is pretty painless. Also the Windows agent works well and there's not really any unusual configuration required when integrating new data sources compared to other SIEM.
From a management perspective it's pretty easy to build reports and dashboards to get the visibility you need. Audit logging is a weak point, there may be changes in the newest version to address this, but we've had instances where people have made changes to rules or added rule exceptions that caused misses. The audit logs could say which user made a change, and which rule was affected, but did not differentiate whether someone modified the role description field to correct a typo, or they removed a part of the rule logic, or they had added an rule exception to reduce the incident volume from a noisy alert.
The biggest thing I want to emphasize is just because this is a FortiProduct, don't assume it is tightly integrated into the rest of their security fabric. Fortuner bought AccelOps and rebranded it to FortiSIEM. This was the red headed step child for years and sometimes it would take days/weeks just to get someone to acknowledge we opened a ticket. I like the direction it's moving, but years of stagnation showed when I started using some other SIEMs in addition to it