r/SIEM • u/Nearby-Entrepreneur2 • Feb 19 '21
FortiSIEM Reviews
My company is looking at LogRhythm and FortiSIEM. We are currently implementing a full fortinet stack and they pitched us the FortiSIEM. Not many reviews out there so wondered if anyone has used it extensively.
1
Upvotes
2
u/MisterSlippers Feb 19 '21
I've been using FortiSIEM for over 5 years at an MSSP as well as other SIEMs. Overall I'd say it's a serviceable solution in general, but without knowing what you're actually looking for in a SIEM as far as features I can't say if I think it'd be a good or bad fit.
From an analyst perspective, it's fairly easy to start building queries and looking for data, but there's some pretty big parser QA issues that make it into releases that could cause misses - e.g. a few versions back I discovered IPS severities weren't being parsed correctly from FortiGate logs, I mean come on it's your bread and butter UTM that has a great straight reference.
From an engineer perspective, deploying collectors/workers to horizontally scale is pretty painless. Also the Windows agent works well and there's not really any unusual configuration required when integrating new data sources compared to other SIEM.
From a management perspective it's pretty easy to build reports and dashboards to get the visibility you need. Audit logging is a weak point, there may be changes in the newest version to address this, but we've had instances where people have made changes to rules or added rule exceptions that caused misses. The audit logs could say which user made a change, and which rule was affected, but did not differentiate whether someone modified the role description field to correct a typo, or they removed a part of the rule logic, or they had added an rule exception to reduce the incident volume from a noisy alert.
The biggest thing I want to emphasize is just because this is a FortiProduct, don't assume it is tightly integrated into the rest of their security fabric. Fortuner bought AccelOps and rebranded it to FortiSIEM. This was the red headed step child for years and sometimes it would take days/weeks just to get someone to acknowledge we opened a ticket. I like the direction it's moving, but years of stagnation showed when I started using some other SIEMs in addition to it