Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
FortiSIEM- Engineer's Guide for deployment and Configuration
Rating: 4.3 out of 5(24 ratings)
149 students

FortiSIEM- Engineer's Guide for deployment and Configuration

A Practical Course for Security Engineers and SIEM Architects
Last updated 5/2025
English
English [Auto],

What you'll learn

  • FortiSIEM Artitecture configuration and deplyment
  • FortiSIEM Rules Dashboard and Reports
  • Integration with all kinds of devices with FortiSIEM
  • SOC best practices with FortiSIEM

Course content

14 sections42 lectures5h 1m total length
  • Introduction on your Trainer0:54

    Meet trainer Kashif, a FortiSIEM and Fortress expert with 20–30 deployments, as he guides you through FortiSIEM deployment and configuration in this course.

  • Licensing Explained3:46

    Understand FortiSIEM licensing driven by events per second, device count, and agent deployments, with examples showing how firewall and Windows logs influence EPs and device counts.

  • FortiSIEM Node Types Part 14:02

    FortiSIEM node types cover an all-in-one supervisor with UI and onboarded devices, where the DB resides, and adding workers—normal, data/query, and keeper—for scalable, high-availability deployments.

  • FortiSIEM Node Types Part 24:57

    Learn FortiSIEM node types—normal workers, data query nodes, keeper nodes—and how the supervisor, collectors, and async data replication enable scalable, high-availability log collection, correlation, and incident management.

  • FortiSIEM Architecture Breakdown 7.1.x , 7.2.x,7.3.x4:27

    Explore FortiSIEM architecture across 7.1.x, 7.2.x, and 7.3.x, detailing supervisor and collector high availability, leader and follower roles, and log flow to the supervisor console.

Requirements

  • Active FortiSIEM instance

Description

FortiSIEM – Engineer's Guide for Deployment and Configuration

Course Description:

This comprehensive, hands-on course is designed for security engineers, SOC analysts, MSSP professionals, and IT administrators who want to master the deployment, configuration, and operational management of Fortinet's FortiSIEM platform. Covering over 300 minutes of in-depth training, this course takes you from foundational concepts to advanced implementation strategies across real-world enterprise and MSSP environments.

FortiSIEM is a powerful, scalable Security Information and Event Management (SIEM) solution that combines security monitoring with performance analytics. Whether you're new to FortiSIEM or looking to refine your deployment and tuning skills, this course equips you with the knowledge and tools needed to build, customize, and maintain a robust security monitoring environment.

What You Will Learn:

  • FortiSIEM Architecture Overview

    • Understanding core components: Supervisor, Worker, Collector, and Database

    • Deployment models for SMBs, Enterprises, and MSSPs

  • Installation and Initial Setup

    • System requirements and sizing for EPS/GB/day

    • VM-based and hardware appliance deployments

    • Network architecture and deployment planning

  • Device Integration and Log Collection

    • Onboarding devices (Fortinet, Cisco, Windows, Linux, Palo Alto, etc.)

    • Configuring syslog, SNMP, WMI, and agent-based collection

    • Troubleshooting parser and log ingestion issues

  • Parser and Event Normalization

    • Custom parser creation for unsupported log sources

    • Debugging and testing event patterns

    • Mapping events to CMDB assets and log types

  • Rules, Alerts, and Correlation

    • Writing detection rules with filters and patterns

    • Use case implementation (Brute Force, Malware Activity, Policy Violations)

    • Alert enrichment and auto-remediation options

  • Dashboards, Reports, and CMDB

    • Building role-based dashboards and KPI widgets

    • Generating compliance-ready reports (PCI-DSS, ISO, NIST)

    • Managing the Configuration Management Database (CMDB)

  • Multi-Tenancy and MSSP Configuration

    • Isolating tenant data and access

    • Designing scalable MSSP architecture

    • Resource allocation and performance optimization

  • System Hardening and Best Practices

    • Backup and disaster recovery planning

    • Retention, storage, and archive configuration

    • Performance tuning and EPS optimization

  • Advanced Topics

    • Threat intelligence (CTI) integration

    • Playbook and incident response automation

    • API usage for integration with external systems (SOAR, ticketing, etc.)

Who Should Take This Course:

  • Security Engineers and Analysts

  • SOC Managers and Architects

  • MSSP Operators

  • Fortinet Partners and Consultants

  • IT Admins seeking in-house SIEM solutions

Prerequisites:

  • Basic knowledge of networking and security operations

  • Familiarity with Fortinet or other security tools (helpful, not mandatory)

  • Understanding of log formats and system logs

Course Features:

  • 5+ hours of video content

  • Hands-on lab demonstrations

  • Real-world implementation scenarios

  • Quizzes and configuration walkthroughs

  • Downloadable documentation templates and scripts

  • Access to a private Q&A forum

Who this course is for:

  • Beginners with FortiSIEM