
Meet trainer Kashif, a FortiSIEM and Fortress expert with 20–30 deployments, as he guides you through FortiSIEM deployment and configuration in this course.
Understand FortiSIEM licensing driven by events per second, device count, and agent deployments, with examples showing how firewall and Windows logs influence EPs and device counts.
FortiSIEM node types cover an all-in-one supervisor with UI and onboarded devices, where the DB resides, and adding workers—normal, data/query, and keeper—for scalable, high-availability deployments.
Learn FortiSIEM node types—normal workers, data query nodes, keeper nodes—and how the supervisor, collectors, and async data replication enable scalable, high-availability log collection, correlation, and incident management.
Explore FortiSIEM architecture across 7.1.x, 7.2.x, and 7.3.x, detailing supervisor and collector high availability, leader and follower roles, and log flow to the supervisor console.
Explore FortiSIEM deployment options across hardware, os packages, and virtualization types (vmware, kvm, hyper-v) plus cloud (aws, gcp, azure) with 64 gb ram and 32 cpu core sizing.
Download the FortiSIEM OVA from the support firmware download, choose the correct package (VMware ESX, Azure, VM, raw drive, hyper-v) and start the download.
Upload the FortiSIEM OVA on VMware ESXi, deploy the supervisor node, and configure network settings with IP, gateway, and subnet. Allocate CPU, RAM, and disk provisioning for data retention.
Log in to the FortiSIEM supervisor node with default credentials, validate disks and mounts, run config FSM to set network, hostname, DNS, test connectivity, and note to snapshot before deployment.
Upload the OVA to ESXi, power on, and configure the collector with minimum four cpu and four gb ram, plus 25 gb os and 100 gb opt disks for logs.
Install the collector, change the default password, configure IP and time zone, set the hostname, verify connectivity, and reboot to integrate with the supervisor.
Log in to the VM IP, view the hardware ID on the licensing page, copy the code, and link it in the customer support portal to obtain the license file.
Navigate asset management to register licenses, update hardware IDs, download and upload license files, and configure enterprise mode, including setting admin credentials, while mounting data disks for a clickhouse stack.
Integrate the collector with the supervisor by configuring worker or supervisor addresses. Then register the collector via the provided command and monitor health until logs flow to the supervisor.
Onboard a worker in FortiSIEM by adding a worker node in VMware, entering the IPv4 address, selecting VM, configuring /dev/sdc, and ensuring communication without extra CLI steps.
Understand log flow in the FortiSIEM architecture: syslog to collector via supervisor, with agents validating licenses; use a collector proxy to reach remote supervisors for SNMP, JDBC, and cloud traffic.
Navigate the FortiSIEM GUI breakdown, exploring dashboards, analytics, CMDB, and incident views. Create dashboards, run queries, map incidents to cases, and plan playbooks with integration options.
Explore the FortiSIEM GUI breakdown: navigate the cmdb with devices, users, and business services, configure reports, rules, and ML jobs, and manage credentials, LDAP, SNMP, collectors, and templates.
Explore clickhouse, an open-source OLAP database with column-wise storage, prized for scalability and replication in FortiSIEM's data correlation and aggregations, with updates not a primary use case.
Explain how keeper clusters manage shards, replicas, and replication in a multi-tenant MSSP setup, with supervisors handling oversight and per-organization shard distribution.
Configure ClickHouse with keeper cluster, shards, and replication across worker nodes, designate data and query nodes, test and deploy, and follow best practices for supervisor and data node placement.
Discover how FortiSIEM integrates devices across cloud services such as AWS, Azure, and GCP, plus servers, apps, and network devices, using JDBC and syslog, with parsers for custom logs.
FortiSIEM deployment for a midsize organization guides integrating firewall, switches, Windows and Linux servers, cloud services, and email security using documentation, SNMP, syslog, and CloudWatch steps.
Learn to integrate Active Directory LDAP users with FortiSIEM to log in using LDAP credentials. Configure credentials, base DN, and external authentication to discover AD users into the CMDB.
Configure SNMP integration in FortiSIEM by setting credentials for SNMP v2 or v3, testing connectivity, and discovering devices to monitor uptime, downtime, and usage.
Learn to integrate VirusTotal and FortiGuard IOC with FortiSIEM: configure external integrations, enter API keys, set up automation policies, and auto-populate reputation for new incidents.
Integrate threat intel into FortiSIEM by enabling IOC services, scheduling hourly updates for malware IP lists, and linking these feeds to rules that trigger alerts.
Discover how FortiSIEM agents validate licenses via the supervisor license controller, with agent communication and usage tracking. Learn to implement a collector proxy for license checks in isolated environments.
Download the FortiSIEM Windows and Linux agents from the support portal and downloads page, choose version 7.2.2, download the zip files via https, and save them for installation.
install windows agent, configure the template, and verify with agent health in FortiSIEM; learn to uninstall, validate licenses, and apply templates for accurate logging.
Demonstrates installing and uninstalling the linux agent, configuring the agent proxy, and configuring the windows template for FortiSIEM deployment.
Explore built-in FortiSIEM reports, create custom reports with the expression builder to capture last log received time, and schedule daily csv or pdf outputs with email alerts.
Learn to create and customize FortiSIEM dashboards using widgets, import reports, and configure charts to monitor device performance, incidents, and user activity.
Master FortiSIEM rule creation and testing by exploring incident triggers, default rule sets, threshold-based alerts, CPU utilization checks, time windows, exceptions, and rule activation.
Explore how to create machine learning rules in FortiSIEM, train clustering models on CPU utilization data, and schedule ML jobs to trigger incidents.
Explore the incidents tab in FortiSIEM, filter by time and device, view risk scores, and drill down to a specific IP to investigate and resolve incidents, including Uber alerts.
Analyze a high-severity FortiSIEM incident by reviewing triggering events and rule summaries, then classify as false positive or escalate via case management and fine-tune rules.
FortiSIEM – Engineer's Guide for Deployment and Configuration
Course Description:
This comprehensive, hands-on course is designed for security engineers, SOC analysts, MSSP professionals, and IT administrators who want to master the deployment, configuration, and operational management of Fortinet's FortiSIEM platform. Covering over 300 minutes of in-depth training, this course takes you from foundational concepts to advanced implementation strategies across real-world enterprise and MSSP environments.
FortiSIEM is a powerful, scalable Security Information and Event Management (SIEM) solution that combines security monitoring with performance analytics. Whether you're new to FortiSIEM or looking to refine your deployment and tuning skills, this course equips you with the knowledge and tools needed to build, customize, and maintain a robust security monitoring environment.
What You Will Learn:
FortiSIEM Architecture Overview
Understanding core components: Supervisor, Worker, Collector, and Database
Deployment models for SMBs, Enterprises, and MSSPs
Installation and Initial Setup
System requirements and sizing for EPS/GB/day
VM-based and hardware appliance deployments
Network architecture and deployment planning
Device Integration and Log Collection
Onboarding devices (Fortinet, Cisco, Windows, Linux, Palo Alto, etc.)
Configuring syslog, SNMP, WMI, and agent-based collection
Troubleshooting parser and log ingestion issues
Parser and Event Normalization
Custom parser creation for unsupported log sources
Debugging and testing event patterns
Mapping events to CMDB assets and log types
Rules, Alerts, and Correlation
Writing detection rules with filters and patterns
Use case implementation (Brute Force, Malware Activity, Policy Violations)
Alert enrichment and auto-remediation options
Dashboards, Reports, and CMDB
Building role-based dashboards and KPI widgets
Generating compliance-ready reports (PCI-DSS, ISO, NIST)
Managing the Configuration Management Database (CMDB)
Multi-Tenancy and MSSP Configuration
Isolating tenant data and access
Designing scalable MSSP architecture
Resource allocation and performance optimization
System Hardening and Best Practices
Backup and disaster recovery planning
Retention, storage, and archive configuration
Performance tuning and EPS optimization
Advanced Topics
Threat intelligence (CTI) integration
Playbook and incident response automation
API usage for integration with external systems (SOAR, ticketing, etc.)
Who Should Take This Course:
Security Engineers and Analysts
SOC Managers and Architects
MSSP Operators
Fortinet Partners and Consultants
IT Admins seeking in-house SIEM solutions
Prerequisites:
Basic knowledge of networking and security operations
Familiarity with Fortinet or other security tools (helpful, not mandatory)
Understanding of log formats and system logs
Course Features:
5+ hours of video content
Hands-on lab demonstrations
Real-world implementation scenarios
Quizzes and configuration walkthroughs
Downloadable documentation templates and scripts
Access to a private Q&A forum