FortiSIEM
Event correlation, UEBA and risk management across the whole estate
Compare all 3 models
Figures are Fortinet’s own — sortable, cited on every product page| Model | Actions | ||
|---|---|---|---|
| FortiSIEM 500G CollectorFSM-500G | 8,000 EPS, 500 SNMP, 200 WMI for performance / 100 WMI for logs | N/A | Details |
| FortiSIEM 2200G SupervisorFSM-2200G | 20,000 EPS with collectors | 10,000 | Details |
| FortiSIEM 3600G SupervisorFSM-3600G | 50,000 EPS with collectors | 10,000 | Details |
How to read these numbers
FortiSIEM correlates security events across Fortinet and third-party sources and adds a CMDB, so an alert arrives attached to the asset it concerns rather than to an IP address someone has to look up.
More on choosing within this range
It is sized in events per second, and the architecture separates collection from analysis. The FSM-500G is a collector benchmarked at 8,000 EPS; the FSM-2200G and FSM-3600G are supervisors rated at 20,000 and 50,000 EPS with collectors, each supporting a recommended maximum of 10,000 UEBA users.
Before you order
What is your actual EPS, at peak?
Not your average — your peak, during an incident, when every device is logging hard. That is when a SIEM must not drop events. We size from a real log sample rather than a device count.
How long must you retain?
Retention is usually set by regulation, not preference. It drives storage more than EPS does and is the line item people forget.
Do you have anyone to run it?
A SIEM nobody watches is an expensive log archive. If you do not have 24/7 eyes, DynaScale's managed SIEM and SOC service is the honest alternative to buying the appliance and hoping.