Security analytics

FortiSIEM

รวม Event, Performance และ Configuration จาก IT และ OT Infrastructure เพื่อทำ Correlation, UEBA, Incident response และ Compliance จากมุมมองเดียว

03Hardware models
ReadyArchitecture workshop
FORTINET SECURITY FABRICFortiSIEM security information and event management interface
Unified security operations

เปลี่ยน Event จำนวนมากให้เป็น Incident ที่จัดการได้

FortiSIEM รวม Discovery, CMDB, Event collection, Analytics, UEBA และ SOAR เพื่อให้ SOC เห็น Dependency ของ IT/OT Infrastructure และตอบสนองจาก Context เดียวกัน

FortiSIEM operations dashboard
01

Discover & Normalize

ค้นหา Asset และรวม Event จาก Cloud, Network, Server, Endpoint, Application และ OT

02

Correlate

เชื่อม Event กับ CMDB, Topology และ Threat context เพื่อแยก Incident สำคัญจาก Noise

03

Detect

ใช้ Rules และ UEBA ตรวจจับพฤติกรรมผิดปกติของผู้ใช้ อุปกรณ์ และ Workload

04

Respond

จัดการ Case และใช้ Automation หรือ Playbook เพื่อประสาน Response กับ Security Fabric

Hardware deployment

FortiSIEM Models

สามารถออกแบบได้ทั้ง Hardware, Virtual, SaaS และ Hybrid ตาม Data volume กับข้อกำหนดขององค์กร

Collector

FSM-500G

8,000 EPS—

รวบรวม Event และ Performance Data ใกล้แหล่งข้อมูลก่อนส่งเข้าสู่ Supervisor

500 SNMP / 200 WMI performance
Supervisor

FSM-2200G

20,000 EPS with collectorsสูงสุด 10,000 UEBA users

Supervisor สำหรับองค์กรที่ต้องการ Correlation, Analytics และ UEBA แบบรวมศูนย์

Distributed collection
Supervisor

FSM-3600G

50,000 EPS with collectorsสูงสุด 10,000 UEBA users

เพิ่ม Event throughput สำหรับ SOC และ Hybrid Infrastructure ขนาดใหญ่

Distributed collection
Architecture & sizing workshop

ออกแบบ FortiSIEM ให้เหมาะกับระบบจริง

ส่งข้อมูลจำนวนผู้ใช้ อุปกรณ์ Traffic, Retention, Site และระบบเดิม ทีม CloudThing จะช่วยวาง Architecture, Sizing และ Scope สำหรับ Pilot

คุยกับผู้เชี่ยวชาญ →