FortiSIEM
Security information and event management with event collection, correlation, UEBA, asset discovery/CMDB, monitoring and security operations workflows.
Overview
FortiSIEM collects and normalizes events from Fortinet and third-party IT/OT sources, correlates activity into incidents, and combines security analytics with asset discovery and operational monitoring.
Architecture
Typical designs use collectors/agents close to event sources, worker/processing nodes sized for ingestion and analytics, and a management/supervisor tier. Distributed deployments should be designed around EPS, retention, search workload, geography, HA and tenant separation.
Common use cases
| # | Use case |
|---|---|
| 1 | Centralized SIEM and log analytics |
| 2 | IT/OT security monitoring |
| 3 | UEBA and behavioral detection |
| 4 | Asset discovery and CMDB |
| 5 | Compliance reporting |
| 6 | SOC incident investigation |
| 7 | Multi-vendor event correlation |
Configuration focus
FortiSIEM is primarily configured through the management interface. Validate integrations, collectors, event parsing, CMDB discovery, correlation rules, notification policies and retention against the deployed FortiSIEM release.
Do not copy configuration steps across releases without checking the documentation for the installed version.
Troubleshooting framework
| Area | What to validate |
|---|---|
| Collection | Confirm the device/integration is supported, credentials are valid, time is synchronized, and events reach the intended collector. |
| Ingestion | Check event rate, parsing/normalization, queue health and whether filters are dropping expected events. |
| Rules | Validate correlation-rule scope, thresholds, time windows and whether prerequisite event attributes are populated. |
| Search | Check retention tier, index/search health and time range before assuming data is missing. |
| Capacity | Compare actual EPS, storage growth and concurrent search load with the deployed sizing model. |
Official documentation & downloads
Lifecycle
Use the InManDis lifecycle explorer to search model/SKU lifecycle records when applicable. Software/SaaS release support does not always follow hardware EOO/EOS rules.
Open EOL / EOS search →