Hey all,
We (a msp) had a talk with Fortinet over the usage of Fortisiem for our customer base. Sounded interesting, but I’m a bit concerned about on prem deployment, hardware scaling and stuff they left out.
Are there any folks here that use the product and if so, what experience do you have?
Hello
As integrator I can't tell you much about its exploitation, however I can share the few things about FortiSIEM deployment:
Yes, we use FortiSIEM as Managed SOC provider. We run it as part of our MSSP-managed SOC environment, hosted in our own data center. It’s a powerful and very scalable MSSP platform. It's easy to integrate new customers with all of their devices and applications. Even the onboarding of unknown applications is easy by creating new parsers and rules.
Overall, FortiSIEM is a solid SIEM choice for a MSSP, but success really depends on good planning, proper deployment, and continuous tuning.
Hi @lithichok,
We are MSSP as well. and run it quite the same way as Alex describes it.
It scales perfectly, but you must prepare for scaling before starting to implement the system (just like any other system as well). But you can start and integrate very fast and the thing we loved when researching for the best SIEM: You usually operate on the GUI, just need to switch on code/db-queries and CLI/shell for tuning, not for the daily tasks.
One thing I found out in various discussions: Don't buy the hardware, always deploy as VM! The hardware has many more tasks to solve you can easily work around when using a VM.
Best,
Christian
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
User | Count |
---|---|
72 | |
25 | |
15 | |
10 | |
10 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.