CAlengua
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
NSE 8
NSE 1 - 7
how long do you have Qradar as SIEM solution? are you happy with Qradar? what did u use before Qradar?We purchased the Qradar Appliances just before Q1 Labs was bought out by IBM, so 18-24 months. It is a good product and has a lot of log source DSM' s and many pre-canned Offense triggers. It' s correlation engine is good and custom offenses are somewhat easy to configure (Basically if you can describe the offense in a sentence or two you can write it) Overall we are happy with it, but it does require some tuning and unfortunately we don' t any dedicated security staff to " own" the system. So it' s not as good as it could be for us. But from a purely Fortigate log point of view the FAZ (or FMG) would win hands down, simply because it can correctly interpret the logs. Prior to getting Qradar we didn' t have a SIEM as such, we had syslog servers to receive, store and backup the logs but nothing that could do correlation. The closest we had was our 2000B FAZ. Regards, Matthew
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.