FortiSIEM Expert & SIEM Implementation Consultant
This is implementation experience, not presales slideware. I have built and operated FortiSIEM in production: Supervisor and Worker clusters, ClickHouse event storage and retention policy, Collectors across distributed sites, custom parsers for devices with no built-in support, and correlation rules that produce incidents a SOC analyst can actually work.
- Production implementation experience
- ClickHouse cluster and retention design
- Custom parser and rule development
What is FortiSIEM?
FortiSIEM is Fortinet's security information and event management platform, positioned by the vendor as the backbone of the security operations team. What separates it from a plain log manager is the combination of correlation with a built-in CMDB. FortiSIEM discovers devices using SNMP, WMI, SSH and cloud APIs, classifies them, and keeps an inventory that rules and reports can reference. Fortinet publishes figures of 1 million plus events per second at the top of the scale, with over 2,800 out-of-the-box rules and 3,500 out-of-the-box reports shipping in the product.
The deployment model is worth understanding before anyone signs a purchase order, because it drives cost. A Supervisor node runs the interface, the rule engine and query coordination. Worker nodes are added when a single Supervisor can no longer absorb the insertion rate or the concurrent query and report load, which in practice is when sustained EPS climbs, when long historical searches start queueing, or when scheduled reports collide with analyst hunting. Collectors sit near the log sources, do the parsing work at the edge, buffer when the link to the Supervisor drops, and forward compressed events back over HTTPS. Event storage on modern builds is ClickHouse, replacing the older EventDB approach where events landed on local disk or an NFS mount. ClickHouse brings columnar compression, hot and warm disk tiers, and retention policies you configure per deployment rather than living with whatever the disk allows.
On current positioning: FortiSIEM still ships under that name and sits inside the Fortinet Security Fabric alongside FortiAnalyzer, FortiSOAR and FortiAI. In 2026 Fortinet launched FortiSOC, a unified cloud-delivered SOC platform that brings SIEM, SOAR and threat intelligence into a single service. Fortinet has been explicit that FortiSOC is an additional offering for customers who want a unified platform, and that the existing individual SOC solutions continue to be enhanced and available. If you already run FortiSIEM on-premises, nothing is being taken away from you, but it is a conversation worth having before a renewal.
Where I Can Help
These are the tasks that actually consume time on a FortiSIEM project, based on running them rather than reading about them.
Supervisor, Worker & Collector Architecture
Sizing the cluster against a real EPS baseline instead of a guess, deciding whether Worker nodes are justified yet, and planning the Supervisor for the query and rule load rather than only the ingestion rate. Includes the license conversation, since FortiSIEM is priced on events per second alongside device and agent counts, and an under-sized EPS entitlement shows up as dropped events at exactly the wrong moment.
ClickHouse Storage & Retention Policy
Designing event storage on ClickHouse with hot and warm tiers mapped to the disks you actually have, then setting online retention and archive policy so the platform ages data out on purpose. Also covers older deployments still sitting on EventDB with local or NFS storage, where the migration path and the storage growth curve need to be modelled before anyone commits to a retention promise.
Collector Rollout & Health Troubleshooting
Deploying Collectors across branch sites, data centres and separate tenant networks, including registration to the Supervisor, buffering behaviour when the WAN drops, and upload tuning. Collector health problems are routine: certificate and registration failures, clock skew, a full event buffer, or a blocked path back to the Supervisor. Knowing which of those it is saves days.
Custom Parser Development
The single most common real task on any FortiSIEM project. When a device has no built-in support, or its logs changed after a firmware upgrade, someone has to write the XML parser: regex patterns, attribute extraction, event type definitions, device and application classification into the CMDB, then testing against captured samples until the fields land where the rules expect them.
Rules, Incidents & the Correlation Engine
Building and tuning correlation rules with sub-patterns, aggregation windows, thresholds and clear conditions so incidents fire on real behaviour and close themselves when it stops. Includes MITRE ATT&CK mapping, notification and remediation policy, watchlists, and the discovery and CMDB work that gives rules meaningful asset context instead of bare IP addresses.
Multi-Tenancy, SAML SSO & Platform Operations
Service Provider mode for MSSP deployments with per-organisation collectors, EPS allocation and role scoping, plus external authentication including SAML single sign-on against Entra ID or Okta with role mapping. Day-two operations too: reading phstatus, and knowing what phQueryMaster, phRuleMaster, phParser and phMonitor are telling you when reports hang or incidents stop firing.
Why FortiSIEM for UAE Organisations?
Security monitoring in the UAE is not a maturity ambition, it is a written requirement. The NESA Information Assurance Standard expects centralised logging, event correlation, monitoring of security events and a working incident response capability, with evidence that logs are retained and reviewed. The CBUAE requirements push licensed financial institutions towards continuous monitoring and a functioning SOC, and DESC in Dubai applies comparable expectations to government-linked entities. ADGM and DIFC data protection rules add breach notification timelines that are impossible to meet if nobody can reconstruct what happened. A SIEM is how those controls get evidenced.
FortiSIEM has a large installed base across the region, and a good part of that is the MSSP and SOC-as-a-service model. Service Provider mode is genuinely built for it: each tenant is an organisation with its own Collectors, its own EPS allocation, its own users and its own scoped views, while the provider runs one Supervisor and Worker cluster behind it. For a UAE customer nervous about data leaving their premises, the Collector sitting inside their own network is a real answer, not a marketing one, because parsing happens locally and the provider sees only what is forwarded. That install mode is chosen at build time, which is exactly the sort of decision worth getting right on day one.
The honest part: FortiSIEM rewards planning and punishes improvisation. Events per second is the licensing unit, so an EPS baseline taken before purchase is the difference between a comfortable deployment and one that drops events during an incident. Storage grows faster than most teams expect once OT, endpoint and cloud sources are added, so retention promises need to be modelled against real ingestion, not a spreadsheet estimate. And when something does go wrong, the answer usually lives in the platform processes rather than the interface: phQueryMaster and phRuleMaster stalling, a Collector buffer filling, a ClickHouse tier running out of room. None of that is a reason to avoid the product. It is a reason to deploy it with someone who has already hit those walls.
Talk to a FortiSIEM Expert
Whether you are scoping a first SIEM, rescuing a deployment that only ingests firewall logs, or planning multi-tenancy for a managed service, I can help.
- Free initial scoping call
- Hands-on implementation, not slideware
- NESA and CBUAE monitoring context
- OSCP-certified security background
Frequently Asked Questions
FortiSOAR and the Wider SOC Build
FortiSIEM and FortiSOAR are routinely deployed together: the SIEM detects and raises the incident, the SOAR platform enriches it and drives the response. I have implementation experience on both. If you are working out how the whole detection and response programme fits together, the SOC and SIEM playbook covers the architecture end to end.
Basim Ibrahim, FortiSIEM Consultant in Dubai
If you are searching for a FortiSIEM consultant in Dubai, a FortiSIEM implementation partner in the UAE, or a FortiSIEM expert for GCC deployment, you have found the right person. I am Basim Ibrahim, a Dubai-based cybersecurity consultant with genuine hands-on FortiSIEM implementation experience, covering Supervisor and Worker cluster builds, ClickHouse event storage, and Collector rollouts across distributed sites.
I deliver FortiSIEM deployment services in Dubai and the UAE from sizing and proof-of-concept through to production handover. That includes FortiSIEM custom parser development for devices with no built-in support, correlation rule and incident tuning on the FortiSIEM correlation engine, CMDB and discovery configuration, FortiSIEM ClickHouse retention policy design, SAML single sign-on and external authentication, and FortiSIEM multi-tenancy for MSSP and SOC-as-a-service providers across the GCC.
Based in Dubai and working across UAE and GCC enterprise environments, with the NESA, CBUAE and DESC monitoring requirements that drive most SIEM projects in the region firmly in scope. An OSCP-certified offensive security background means the detection content I build reflects how attacks actually unfold, not just what shipped in the default rule pack.