
The implementation of FortiSIEM follows a structured approach:
Needs Assessment & Planning
Define security objectives, compliance requirements, and scalability needs.
Identify data sources (firewalls, endpoints, cloud services) to be integrated.
Infrastructure Preparation
Set up necessary hardware or virtual environments.
Ensure system requirements (CPU, storage, network bandwidth) are met.
Software Installation & Configuration
Deploy FortiSIEM components (Supervisor, Worker, Collectors).
Configure network settings, user roles, and access controls.
Integration with Data Sources
Connect FortiSIEM to firewalls, endpoint security, cloud platforms, and log sources.
Enable log forwarding and parsing from different sources.
Fine-Tuning & Policy Customization
Set up correlation rules, dashboards, and reports tailored to business needs.
Implement threat intelligence feeds and behavior analytics.
User Training & Knowledge Transfer
Conduct training sessions for security analysts and administrators.
Provide documentation and best practices for incident response.
Testing & Optimization
Run test scenarios for threat detection and alerting.
Adjust configurations for noise reduction and false positive minimization.
Go-Live & Continuous Monitoring
Deploy FortiSIEM in production mode with 24/7 monitoring.
FortiSIEM can be customized to fit specific business needs through various configurations, integrations, and automation features. Below are key aspects of its customization:
Supports ingestion of logs from on-premises, cloud, and hybrid environments.
Custom log parsers can be created for unsupported devices.
Allows custom tagging and categorization of logs for better event correlation.
Users can create custom correlation rules based on unique security policies.
Supports custom SIEM analytics and behavioral anomaly detection.
Allows the tuning of alert thresholds to minimize false positives.
Drag-and-drop interface for creating custom security dashboards.
Customizable report templates for compliance (PCI-DSS, HIPAA, GDPR, ISO 27001, etc.).
Role-based access control (RBAC) to provide different users with personalized views.
Custom connectors & APIs to integrate with other SIEMs, SOAR, EDR, and ITSM tools.
Pre-built integrations with security vendors (Palo Alto, Cisco, AWS, Azure, Google Cloud, etc.).
Supports custom automation scripts via REST API and Python.
Users can create custom playbooks for automated incident response.
Enables custom notifications & alerts via email, SMS, Slack, Microsoft Teams, etc.
Can integrate with custom ticketing systems for case management (e.g., ServiceNow, Jira).
Multi-tenant support allows customization for MSPs and enterprises.
Custom user roles & permissions to control access to data and dashboards.
Granular security policies per business unit, department, or geography.
Supports custom machine learning models for behavioral analysis.
Custom tuning of UEBA (User and Entity Behavior Analytics).
FortiSIEM offers a range of training and support options to assist new users in effectively deploying and managing the system. These resources are designed to cater to various learning preferences and provide in-depth knowledge of FortiSIEM features and functionalities.
Training Programs:
FortiSIEM Analyst Course: This course focuses on teaching users how to utilize FortiSIEM for searching, enriching, and analyzing events within a managed security service provider (MSSP) environment. Participants will learn to perform real-time and historical searches, build advanced queries, and manage security incidents.
Advanced Analytics Course: Aimed at users operating in multi-tenant environments, this course delves into the architecture of rules, incident generation, baseline calculations, remediation methods, and the integration of the MITRE ATT&CK framework with FortiSIEM.
OT Security Course: This program educates users on designing, deploying, administering, and monitoring FortiSIEM alongside other Fortinet products to secure operational technology (OT) infrastructures.
FortiSIEM Parser Course: A specialized two-day course that guides users in creating custom parsers to extend FortiSIEM capabilities to recognize unknown devices and custom applications with unique log formats.
Support Resources:
Self-Paced Online Training: Fortinet provides free self-paced courses covering various aspects of FortiSIEM, allowing users to learn at their own convenience.
Instructor-Led Training: For a more structured learning experience, users can enroll in instructor-led courses that offer interactive sessions and hands-on labs.
On-Demand Labs: To reinforce learning, Fortinet offers on-demand labs that provide practical, hands-on experience with FortiSIEM in a controlled environment.
FortiSIEM implements a set of security measures to protect data, focusing on operating system (OS) security, network security, and application security.
Operating System Security:
Strong Cryptographic Algorithms: FortiSIEM operates in both FIPS (Federal Information Processing Standards) and non-FIPS modes. In FIPS mode, it exclusively employs FIPS-compliant cryptographic algorithms, ensuring robust data encryption. Non-FIPS mode supports TLS 1.2 and 1.3 protocols with secure cipher suites.
Public CA Signed SSL Certificates: To safeguard external communications, FortiSIEM supports the use of public Certificate Authority (CA) signed SSL certificates, enhancing the authenticity and security of data exchanges.
Disk Encryption: FortiSIEM allows encryption of specific disks, such as those holding the Postgres database (/cmdb), device configurations (/svn), and logs (/data). This measure prevents unauthorized access to sensitive data by encrypting storage media.
Network Security:
Port Management: The system permits only essential ports required for its operations, reducing potential entry points for unauthorized access. Administrators can close unused ports and change default ports for services like HTTPS and SSH to non-standard ports, enhancing security.
Interface Control: FortiSIEM provides the capability to disable unused network interfaces, minimizing exposure to potential network-based threats.
Application Security:
Password Policies: The platform enforces strong password policies, requiring passwords to be between 8 and 64 characters and include at least one letter, one numeric character, and one special character. This policy applies to both SSH and GUI access, ensuring robust authentication mechanisms.
FortiSIEM releases updates regularly to enhance functionality, address security vulnerabilities, and ensure compatibility with underlying operating systems. The update process encompasses both application and operating system (OS) components, each managed through distinct procedures.
Application Updates: FortiSIEM application updates are released periodically, introducing new features, performance improvements, and bug fixes. For instance, version 7.3.0 was released on January 7, 2025, incorporating Rocky Linux OS 8.10 patches up to December 6, 2024, and updating PostgreSQL to version 16.6.
To manage these updates, FortiSIEM provides detailed upgrade guides outlining the necessary steps to transition from earlier versions to the latest release. These guides ensure that administrators can perform upgrades systematically, minimizing potential disruptions.
Operating System Updates: FortiSIEM operates on Rocky Linux and maintains its own repositories to manage OS updates. The engineering team monitors updates from Rocky Linux and, upon identifying critical vulnerabilities, tests and integrates necessary patches into FortiSIEM repositories. This approach allows customers to apply essential OS updates without waiting for a full application release.
Administrators can update the OS independently by executing specific commands, ensuring that their systems remain secure and up-to-date. This flexibility is particularly beneficial for addressing critical vulnerabilities promptly.
Update Management: FortiSIEM update management strategy emphasizes both proactive monitoring and user autonomy. By providing timely application releases and maintaining dedicated OS repositories, FortiSIEM ensures that users can keep their systems current. Comprehensive documentation supports administrators throughout the update process, facilitating smooth transitions and maintaining system integrity.
FortiSIEM provides robust data retention and management policies, allowing organizations to control the duration and storage of their event data. Administrators can establish retention policies specifying which events are retained and for how long in both online and archive event databases. These policies can be tailored based on event attributes such as organization, reporting device, and event type.
Regarding data portability, FortiSIEM enables the restoration of archived data for querying and analysis. Administrators can restore archived event data to the system, making it accessible for standard queries and investigations. This functionality ensures that organizations can retrieve and analyze historical data as needed.
FortiSIEM policies on contract renewal and cancellation vary depending on the deployment model—whether it's an on-premises solution or the FortiSIEM Cloud service.
FortiSIEM Cloud:
Automatic Shutdown Upon Expiry: When a FortiSIEM Cloud subscription expires, the associated cloud instances are automatically shut down without a grace period. Users lose access to these instances immediately upon contract expiration. All data generated by FortiSIEM Cloud, including event logs and incidents, is automatically removed from the platform within 14 days post-expiry.
License Registration and Renewal: To register or renew a FortiSIEM Cloud license, users must have a FortiCloud account and purchase the appropriate product SKUs. Upon purchase, service contract registration codes are sent to the registered email address. Users can then register their entitlements or upgrade existing ones through the FortiCare portal.
On-Premises FortiSIEM:
Backdating Policy: For on-premises deployments, if a subscription lapses and is renewed after the expiration date, Fortinet's policy is to backdate the renewal to the original expiration date. This means that if a subscription expired three months ago and is renewed today, the new subscription would cover the period from the original expiration date, effectively providing nine months of service on a one-year renewal. However, backdating is limited to a maximum of six months, ensuring that users do not lose more than six months of service.
Extended Renewals: Purchasing multi-year contracts (e.g., two or more years) may offer flexibility regarding backdating. In such cases, Fortinet may choose not to backdate the renewal, providing a full term from the date of purchase. It's advisable to confirm specific terms with a Fortinet representative or authorized reseller.
General Considerations:
Continuous Coverage: Fortinet designs its support and subscription services to be continuous. To avoid service interruptions, it's recommended to renew contracts before the expiration date. A lapse in service can lead to backdated renewals, as described above.
FortiSIEM is designed to assist organizations in meeting a variety of regulatory compliance standards by providing out-of-the-box support and pre-built reports for several key frameworks. These include:
Payment Card Industry Data Security Standard (PCI DSS): FortiSIEM offers predefined reports and monitoring tools to help organizations adhere to PCI DSS requirements, ensuring the protection of cardholder data.
Health Insurance Portability and Accountability Act (HIPAA): The platform includes policies and reporting features that facilitate compliance with HIPAA regulations, safeguarding sensitive patient information.
Sarbanes-Oxley Act (SOX) with COBIT guidelines: FortiSIEM provides tools to monitor and report on controls related to financial reporting, aiding in SOX compliance.
General Data Protection Regulation (GDPR): The system assists in tracking and demonstrating compliance with GDPR mandates, focusing on the protection of personal data within the European Union.
International Organization for Standardization (ISO) 27001: FortiSIEM supports the implementation and monitoring of an Information Security Management System (ISMS) in line with ISO 27001 standards.